{
  "id": 9527543,
  "title": "cPanel fixes calendar permissions flaw affecting shared servers",
  "url": "https://urgent.news/2026/09/24/cpanel-fixes-calendar-permissions-flaw-affecting-shared-servers",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T07:17:57.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/cpanel-fixes-calendar-permissions-flaw-affecting-shared-servers/"
  },
  "original_language": "en",
  "account": "cPanel, a web hosting control panel provider, has released security updates to address a critical permissions vulnerability affecting its shared server hosting system. The flaw, identified as CVE-2026-68490, allows a local user on a shared server to view calendar events and contact information belonging to other hosting accounts. The vulnerability stems from incorrect permissions in cPanel's CalDAV and CardDAV functionality, which cPanel has since patched across various versions. Administrators are advised to update to the latest patched release to prevent unauthorized access to other users' sensitive data. Despite the severity of the issue, successful exploitation is limited to reading calendar events and contacts, and the vulnerability does not grant attackers root access to the server. cPanel has acknowledged the contribution of security researcher Ali Mustafa in responsibly disclosing the flaw.",
  "summary": "cPanel has issued security updates for a high-severity permissions vulnerability that could allow a local user on a shared server to read calendar events and contact information belonging to other hosting accounts. The flaw, tracked as CVE-2026-68490, affects cPanel and WHM version 120 and later. cPanel said the problem stemmed from incorrect permissions in its CalDAV and CardDAV functionality,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}