cPanel Patched CalDAV and CardDAV Vulnerability

The software update addresses a security flaw that enabled unauthorized data access on shared servers.

Updated on Sept. 24, 2026 in Cybersecurity

cPanel Patched CalDAV and CardDAV Vulnerability

Live Poll

Do you trust shared hosting services to keep your personal data secure from other users?

cPanel released patches for a security vulnerability, identified as CVE-2026-68490, affecting its CalDAV and CardDAV implementation. The update remediates a flaw that allowed local users on shared hosting servers to access contacts and calendar events from other accounts.

Why it matters

The vulnerability stemmed from incorrect permissions in the software's architecture, which posed a significant data privacy risk for shared hosting environments. Applying the patch is necessary to prevent unauthorized users from harvesting sensitive information stored within these accounts.

The security vulnerability, CVE-2026-68490, impacts cPanel/WHM version 120 and later. It is caused by improper permissions within the system's CalDAV and CardDAV implementation.

The players

cPanel

cPanel is a widely used web hosting control panel software that provides a graphical interface and automation tools for server management.

The details

The flaw specifically allowed local users on shared servers to circumvent account isolation and view sensitive calendar and contact data belonging to other users. cPanel issued the update to correct these permissions and restore expected data security controls.

Timeline

  1. September 24, 2026: cPanel officially released the security patches for the vulnerability.

The Tech Race

This update reinforces the security standards of the cPanel/WHM software platform. It highlights the ongoing industry effort to harden multi-tenant environments against lateral data access.

Server administrators must update their systems to version 120 or later to ensure account data remains isolated. Failure to apply the patch leaves stored calendar and contact information accessible to other users on the same server.

The takeaway

Maintaining up-to-date server software is critical to protecting user privacy in shared hosting environments. Administrators should prioritize security patches immediately upon release to mitigate risks posed by permission-based exploits.

Further reading

For broader insights on securing server infrastructure, visit the Cybersecurity section.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you trust shared hosting services to keep your personal data secure from other users?