cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel patched CVE-2026-68490, which lets local users on shared servers read other accounts' calendars and contacts.
cPanel patched CVE-2026-68490, an incorrect-permission issue in its CalDAV and CardDAV implementation affecting cPanel/WHM version 120 and later. A local user on a shared server can read other hosting accounts' calendar events and contacts, but cannot change that data or obtain root access. Fixed builds are 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11 or later; the updates also repair existing storage permissions. NVD had not assigned a CVSS score at publication, and the report does not describe observed exploitation.