HackerFeeds

CyberSecurity News

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News
· September 23, 2026

AI summary

A vulnerability in cPanel's CalDAV and CardDAV service allows users with a hosting account to execute code with root privileges, giving them complete control over the server. Additionally, a bug was found in the WP Toolkit plugin, which enables an account holder to modify databases belonging to other accounts. cPanel has issued updated versions to address both issues.

Read the full article at The Hacker Newsthehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.