New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Swati KhandelwalSep 23, 2026Vulnerability / Web Security A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other accounts'…
CVEs: CVE-2026-87899, CVE-2026-87900, CVE-2026-68490
Original source: thehackernews.com