cPanel Patched Security Flaw in Shared Hosting Servers
The update secures CalDAV and CardDAV implementations that previously allowed unauthorized cross-account data access.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Do you trust shared hosting services to keep your personal data secure from other users?
cPanel has released security patches for a vulnerability in its CalDAV and CardDAV implementation, identified as CVE-2026-68490. The flaw impacts cPanel/WHM version 120 and later, potentially allowing local users on shared servers to access unauthorized contact and calendar data.
Why it matters
Incorrect permission settings in software services create risks for multi-tenant environments where security isolation is required between users. This patch ensures that data containers remain siloed, preventing users on the same physical server from accessing information they do not own.
The vulnerability affects cPanel/WHM version 120 and later, stemming from an incorrect permissions configuration within the software's CalDAV and CardDAV components. This flaw compromises the logical separation between tenants on shared hosting infrastructure.
The players
cPanel
A prominent developer of server management software widely used for website hosting administration and automation.
The details
The vulnerability involves CalDAV (a protocol used to synchronize calendar data) and CardDAV (a protocol for synchronizing contacts). By failing to enforce strict permission boundaries, the software allowed a local user to bypass authentication checks that would normally block access to external database records. The patches update these internal permission protocols to ensure that data requests are validated against the specific account's authorization level.
Timeline
September 24, 2026: cPanel released official patches to address the security vulnerability.
The Tech Race
This update follows standard maintenance cadences for the cPanel/WHM ecosystem, which remains the dominant control panel for Linux-based shared hosting. The race to maintain these environments involves constant auditing of permission-based protocols against unauthorized local access attempts.
Administrators using cPanel/WHM version 120 or newer should apply the provided patches immediately to prevent unauthorized data exposure. Shared hosting users do not need to take action, as the responsibility for applying these software updates rests with the server provider.
The takeaway
Maintaining strict permission boundaries is critical for multi-tenant software security. Administrators should verify their cPanel/WHM version to confirm whether they are running the patched build to eliminate potential cross-account data access.
Further reading
For more on evolving threats to server infrastructure, explore the Cybersecurity section.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you trust shared hosting services to keep your personal data secure from other users?






