Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

cPanel Vulnerability Allows Hosting Accounts to Execute Code as Root, Gain Full Server Control

A flaw in cPanel’s CalDAV/CardDAV services lets any hosting account run code as root, giving full server control, while a WP Toolkit bug enables cross‑account database changes. The issue underscores the need for strong access‑control evidence and continuous control mapping to stay audit‑ready.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

cPanel Vulnerability Allows Hosting Accounts to Execute Code as Root, Gain Full Server Control

What Happened — A flaw in cPanel’s CalDAV and CardDAV services lets any account with a cPanel hosting login execute code with root privileges, effectively taking full control of the underlying server. A second issue in the WP Toolkit plugin permits an account holder to modify databases belonging to other customers. cPanel has issued patched versions for both components.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk when privileged access is not properly isolated – a core access control and privilege management objective that continuous‑control programs must monitor and evidence.
  • Highlights the need for configuration‑management evidence to prove that software components are kept up‑to‑date and that segregation controls are enforced.
  • Aligns with Verisq’s Control Mapping capability, which helps organizations collect, map, and continuously verify evidence that such controls are operating as intended.

Who Is Affected

  • Web‑hosting providers and managed service providers that deploy cPanel.
  • SaaS platforms that rely on cPanel for customer site provisioning.
  • End‑customers whose sites are hosted on vulnerable instances.

Recommended Actions

  • Deploy the latest patched cPanel releases immediately across all servers.
  • Conduct a privileged‑access review to confirm that no account retains unnecessary root rights.
  • Verify that isolation controls (e.g., containerization, chroot jails) are enforced and documented as evidence.
  • Update your control‑mapping inventory to reflect the new version status and any remediation steps taken.
  • Enable continuous monitoring for anomalous root‑level activity and retain logs as audit‑ready evidence.

Source: The Hacker News

Technical Notes

  • Attack Vector: Exploitation of CalDAV/CardDAV service logic flaw; cross‑account database manipulation via WP Toolkit plugin.
  • Impact: Potential full server compromise, lateral movement across hosted accounts, and data exposure.
  • Patch Status: Fixed versions released by cPanel; no CVE identifier disclosed publicly at time of reporting.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →