hacker-news · Crawled Sep 23, 2026
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Read original article ↗AI Summary
cPanel disclosed three security flaws, two of which are critical, allowing privilege escalation and unauthorized access on shared hosting servers. CVE-2026-87899 enables a logged-in cPanel account holder to execute code as root via the CalDAV and CardDAV service, achieving full server control. CVE-2026-87900 affects the WP Toolkit plugin, allowing a user to modify databases belonging to other accounts. CVE-2026-68490 permits local users to read calendar and contact data from other accounts, though not modify it or escalate privileges. All vulnerabilities have been patched, but no exploitation in the wild has been reported.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.