MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via The Hacker News

cPanel Vulnerability Allows Hosting Accounts to Gain Root Access

Image via The Hacker News
Image via The Hacker News

A flaw in cPanel's CalDAV and CardDAV service lets any hosting account execute code as root, granting full server control. A second bug in the WP Toolkit plugin allows cross-account database changes. cPanel has released fixes for both.

Expanded Detail

The CalDAV and CardDAV service flaw is especially dangerous because it transforms a standard hosting account into one with root-level privileges. An attacker who gains access to any single account on a shared server could then seize control of the entire machine, including all other accounts and data residing on it.

The WP Toolkit vulnerability operates through a separate mechanism, enabling database modifications that cross account boundaries. Together, these issues present a layered threat to hosting environments. cPanel has already distributed patches for both problems, and administrators are advised to apply them promptly to close the exposure windows.

Context

The combined impact of these vulnerabilities could be substantial for shared hosting providers, where many websites often share a single server. A root-level compromise could expose customer data, alter site content, or enable further malicious activity. Small businesses and individual users relying on shared hosting may face service interruptions or data loss. The cross-account database flaw could also affect WordPress deployments specifically. While fixes exist, administrators who delay updates may leave their infrastructure vulnerable to exploitation.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
WordPress Core CSRF bug enables remote code execution via theme preview · Cybersecurity
D-Link flags unpatched critical flaw in legacy routers with public exploit · Cybersecurity
Check Point confirms active attacks on VPN gateway vulnerability, adds second zero-day to advisory · Cybersecurity
WordPress zero-day under active attack as exploit chain moves to file writes · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control.” Browse more stories.