chiprook
← Security
SecuritySeptember 23, 2026, 19:16

cPanel flaw lets a hosting account run code as root and take over the server

cPanel disclosed on September 22 a flaw in its CalDAV and CardDAV service that lets any hosting account holder run code as root and take full control of the server. A second bug in the WP Toolkit plugin allows an account holder to alter databases belonging to other accounts. Fixed versions have been released for both.

cPanel flaw lets a hosting account run code as root and take over the server
#CPanel#WordPress
Read next
Security

UAE and Saudi Arabia Absorb Half of Gulf Cyberattacks

Security

Eclypsium: attackers shift focus to infrastructure management systems

Security

FBI investigating alleged ShinyHunters breach of its jobs site

Security

Two critical vulnerabilities found in Radicle network protocol