cPanel has released fixes for CVE-2026-68490, an incorrect-permissions issue in its CalDAV/CardDAV functionality. The vulnerability can allow a local user on a shared server to read calendar events and contact data belonging to other accounts.

Why shared-hosting operators should care

The issue affects tenant separation rather than granting remote or root access. Even so, calendars and contacts can contain sensitive operational information, and the flaw underscores the importance of keeping hosting control-plane software current.

Recommended action

  • Review servers running cPanel/WHM version 120 and later.
  • Update to cPanel/WHM 11.134.0.57, 11.136.0.41, or 11.138.0.8 or later, as applicable; WP Squared users should use 11.138.1.11 or later.
  • Review local-account access controls and shared-hosting tenant isolation.

Source: GBHackers: cPanel permissions flaw, citing cPanel’s September 22 security notice.

By Allan