cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel patched CVE-2026-68490, which lets local users on shared servers read other accounts' calendars and contacts.
cPanel patched CVE-2026-68490, an incorrect-permission issue in its CalDAV and CardDAV implementation affecting cPanel/WHM version 120 and later. A local user on a shared server can read other hosting accounts' calendar events and contacts, but cannot change that data or obtain root access. Fixed builds are 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11 or later; the updates also repair existing storage permissions. NVD had not assigned a CVSS score at publication, and the report does not describe observed exploitation.
- CVE-2026-68490 is an incorrect CalDAV/CardDAV permission flaw, CWE-732.
- A local user can read, but not modify, other accounts' calendars and contacts.
- Affected releases are cPanel/WHM 120 and later on shared servers.
- Fixes include 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11.
- NVD had not assigned a CVSS score, and in-the-wild exploitation was not reported.
Vulnerabilities mentionedAll →
- CVE-2026-684908.2—CalDAV/CardDAV Permission Flaw in cPanel Lets Local Users Read Other Accounts' Datapublished · cPanel (cPanel, L.L.C. / WebPros) cPanel & WHM (CalDAV/CardDAV calendar and contacts service)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-68490 | CalDAV/CardDAV Permission Flaw in cPanel Lets Local Users Read Other Accounts' Data CVE-2026-68490 is an incorrect permission assignment (CWE-732) affecting the CalDAV/CardDAV calendar and address book service in cPanel & WHM, based on the related reporting naming cPanel. Any user who already has an account on the same server (for example, another shared-hosting tenant or a low-privilege local user) can access other accounts' calendar and contact data, because the service fails to enforce per-account boundaries on those resources. The attack is local, requires only low privileges, and no user interaction, yielding high confidentiality impact — including exposure of data in connected/subsequent systems per the CVSS 4.0 vector — but no integrity or availability impact. Practically, an attacker gains other tenants' calendars and address books, which frequently contain sensitive personal, corporate, and credential-adjacent information (meeting details, contacts, reset addresses). There is no CISA KEV entry and no public proof of concept, so exploitation status is currently none known. |
Full article403 words · extracted from gbhackers.com · click to collapse
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation.
This flaw could allow a local user on a shared server to access calendar events and contacts from other hosting accounts. The issue affects cPanel/WHM version 120 and later, highlighting the risks associated with tenant isolation in shared-hosting environments.
cPanel Permissions Flaw
The vulnerability, tracked as CVE-2026-68490, originates from improper permission assignments within cPanel’s CalDAV and CardDAV functionalities.
An attacker exploiting this flaw could access sensitive calendar and address-book data from other accounts on the server. The National Vulnerability Database classifies this issue as CWE-732, or “Incorrect Permission Assignment for Critical Resource.”
This vulnerability is particularly concerning for shared-hosting environments, where multiple customers, resellers, or local system users operate on the same cPanel/WHM server.
While exploitation requires local access to the affected server, it can compromise the necessary separation between hosting tenants.
According to cPanel, an attacker who successfully exploits this vulnerability can read other accounts’ calendar events and contacts. However, the exploit does not permit any modifications to the exposed calendar or contact data, nor does it grant root-level access to the server.
The affected releases include cPanel/WHM version 120 and later. cPanel has issued fixes in the following versions:
- cPanel/WHM 11.134: 11.134.0.57 or later
- cPanel/WHM 11.136: 11.136.0.41 or later
- cPanel/WHM 11.138: 11.138.0.8 or later
- WP Squared: 11.138.1.11 or later
The National Vulnerability Database (NVD) has identified vulnerable cPanel ranges before the fixed releases in the 11.134, 11.136, and 11.138 branches. At the time of publication, NVD had not yet assigned a CVSS base score to this CVE.
The patches do more than just protect newly created CalDAV and CardDAV data; they also correct the permissions for new calendar and address-book storage and repair any improper permissions that may already exist in customer accounts.
Administrators should prioritize patching systems that host multiple customers or allow shell access, especially if CalDAV/CardDAV synchronization is enabled.
After applying the updates, teams should verify the installed cPanel version, review local account access controls, and investigate any unusual access to calendar or address-book storage.
Security researcher Ali Mustafa, also known as rz1027, responsibly disclosed the vulnerability.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.