Find notable cyber news and cases, enriched with sources, timelines, and signals.

CPanel CalDAV and CardDAV calendar/contact read flaw (CVE-2026-68490)

Vulnerability
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

cPanel fixed CVE-2026-68490, a CalDAV and CardDAV flaw that lets a local user read other accounts' calendar events and contacts on affected hosting systems. The bug is confined to confidentiality, but it still exposes private scheduling and relationship data across accounts. cPanel & WHM and WP Squared received fixed builds, and the vendor said the update also repairs related permissions.

Related Happenings

CPanel CalDAV and CardDAV root code execution security flaw (CVE-2026-87899)

Vulnerability
H score33 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

How related: A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.

About this happening: cPanel's fix for CVE-2026-87899 closes a CalDAV and CardDAV flaw that let a logged-in hosting account run code as root, putting affected servers at risk of full cont...

WP Toolkit cross-account database modification security flaw (CVE-2026-87900)

Vulnerability
H score1 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

How related: A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.

About this happening: The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting system...

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

CPanel CVE-2026-41940 mitigation guidance

Advisory/Mitigation
H score89 First: 30.04.2026 14:40 Last: 30.04.2026 14:40 Sources 1

About this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...

Timeline

  1. 23.09.2026 15:16 2 articles · 2h ago

    cPanel patches CVE-2026-68490 calendar and contact read flaw

    Initial Disclosure

    cPanel said on September 22, 2026 that CVE-2026-68490 in CalDAV and CardDAV lets a local user on an affected shared hosting server read other accounts' calendar events and contacts without changing them or gaining root access. The vendor released fixed builds for affected cPanel & WHM release lines and WP Squared, and said the update also repairs calendar and contact permissions for existing accounts.

    Show sources