hacker-news · Crawled Sep 23, 2026

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

Read original article ↗

AI Summary

cPanel disclosed three security flaws, two of which are critical, allowing privilege escalation and unauthorized access on shared hosting servers. CVE-2026-87899 enables a logged-in cPanel account holder to execute code as root via the CalDAV and CardDAV service, achieving full server control. CVE-2026-87900 affects the WP Toolkit plugin, allowing a user to modify databases belonging to other accounts. CVE-2026-68490 permits local users to read calendar and contact data from other accounts, though not modify it or escalate privileges. All vulnerabilities have been patched, but no exploitation in the wild has been reported.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.