Back to all news
Security

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News·September 23, 2026·1 min read
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A cPanel flaw in its CalDAV and CardDAV service lets any hosting account holder run code as root and take full server control, the company said on September 22. A second bug in the WP Toolkit plugin allows changing databases of other accounts. cPanel has released fixed versions for both.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store