New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
AI-summarised brief · reviewed before publication
A vulnerability in cPanel’s CalDAV and CardDAV services allows any account holder to execute code with root privileges, granting full server control. A separate flaw in the WP Toolkit plugin lets users modify databases belonging to other accounts. cPanel released patches for all three issues, including a third flaw that permits reading but not altering other users’ calendar data. The root flaw requires only a cPanel account, meaning any shared‑hosting customer could exploit it. The advisories provide no exploitation details or pre‑update checks.
💡 Why It Matters
- · The flaw exposes shared‑hosting environments to total takeover, undermining the isolation that hosts promise to their customers.
- · It forces providers to prioritize urgent patching and reassess their security posture.