Vulnerabilities & PatchesEmerging1 src
New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts
cPanel has patched three newly disclosed security vulnerabilities that threaten tenant isolation on shared-hosting servers, including a permissions flaw that exposes other users’ calendars and contacts.
The September 22, 2026, security release addresses CVE-2026-68490 alongside a root privilege-escalation bug and a WP Toolkit cross-account database vulnerability, making immediate updates essential for hosting providers and server administrators.
cPanel Vulnerability
Tracked as CVE-2026-68490, the primary vulnerability stems from incorrect permissions in cPanel’s CalDAV and CardDAV functionality. A local user with access to the same server could exploit the weakness to read calendar events and contact information belonging to other cPanel accounts.
The flaw breaks a key security boundary in multi-tenant environments, where customers expect their account data to remain isolated.