$ techbeacon▋
CVE & Exploits

Local User Exploit on Shared cPanel Servers Exposes Calendar and Contact Data

Local User Exploit on Shared cPanel Servers Exposes Calendar and Contact Data

A critical security flaw in cPanel's CalDAV and CardDAV services has been patched after it was discovered that local users on shared hosting environments could read calendar events and contact information belonging to other accounts. The vulnerability, catalogued as CVE-2026-68490, stems from improper file‑system permissions that allowed unauthorized access to data stored in the WebDAV directories used by the platform.

The issue was first brought to light by the security research collective GBHackers, who demonstrated that a user with a standard shell account on a multi‑tenant server could navigate to another customer's data store and retrieve private scheduling details and address book entries. Because many web hosts rely on cPanel to manage numerous client sites on a single machine, the flaw had the potential to expose sensitive personal and business information across a wide range of services.

cPanel responded by releasing an emergency update that corrects the permission settings and tightens access controls for the CalDAV/CardDAV modules. Administrators are urged to apply the patch immediately and verify that their servers are running the latest version of the software. The vendor also provided guidance on reviewing audit logs for any signs of unauthorized data retrieval that may have occurred before the fix was deployed.

While the vulnerability is classified as local – meaning it requires a valid user account on the host – the shared nature of many hosting arrangements amplifies the risk. Attackers could exploit compromised credentials, weak passwords, or other entry points to gain a foothold, then leverage the flaw to harvest calendar entries that might contain meeting times, project details, or personal appointments. Security experts note that the exposure of contact lists can also facilitate phishing campaigns, as attackers gain verified email addresses and personal connections.

Industry observers say the incident underscores the importance of rigorous permission management in multi‑tenant platforms. cPanel has a long history of providing convenient tools for webmasters, but the complexity of integrating multiple protocols like CalDAV can introduce subtle bugs. Going forward, the company has pledged to enhance its internal testing procedures and to work more closely with the security community to identify similar risks before they reach production environments.

Customers of hosting providers that use cPanel should check with their service operators to confirm that the patch has been applied. Those who suspect their data may have been accessed are advised to monitor for unusual activity, rotate passwords, and consider resetting shared calendar and contact configurations. The broader lesson for the industry is clear: even seemingly low‑risk features such as calendar syncing must be scrutinized for privilege‑escalation vectors in shared hosting scenarios.

Source: GBHackers
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related