cPanel fixes calendar permissions flaw affecting shared servers
cPanel has issued security updates for a high-severity permissions vulnerability that could allow a local user on a shared server to read calendar events and contact information belonging to other hosting accounts. The flaw, tracked as CVE-2026-68490, affects cPanel and WHM version 120 and later. cPanel said the problem stemmed from incorrect permissions in its CalDAV and CardDAV functionality,…
cPanel, a web hosting control panel provider, has released security updates to address a critical permissions vulnerability affecting its shared server hosting system. The flaw, identified as CVE-2026-68490, allows a local user on a shared server to view calendar events and contact information belonging to other hosting accounts.
The vulnerability stems from incorrect permissions in cPanel's CalDAV and CardDAV functionality, which cPanel has since patched across various versions. Administrators are advised to update to the latest patched release to prevent unauthorized access to other users' sensitive data. Despite the severity of the issue, successful exploitation is limited to reading calendar events and contacts, and the vulnerability does not grant attackers root access to the server. cPanel has acknowledged the contribution of security researcher Ali Mustafa in responsibly disclosing the flaw.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.