Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: shared-hosting (7 articles)Clear

cPanel flaw lets any hosting account run code as root and seize the server

cPanel disclosed a flaw in its CalDAV and CardDAV service, CVE-2026-87899, that lets any logged-in hosting account run code as root and take full control of the server. It lists no requirement beyond having an account, so on a shared server any customer, or anyone with a stolen customer login, could exploit it. cPanel also fixed a WP Toolkit bug, CVE-2026-87900, letting an account holder alter other accounts' databases, and a third issue, CVE-2026-68490, letting a local user read other accounts' calendars and contacts. Fixes ship across cPanel and WHM version 120 and later branches, including builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 or later, plus WP Toolkit 6.11.3.

Check
Identify cPanel and WHM servers on version 120 branches, apply the fixed builds now, and prioritize shared hosting where any customer account is a threat.
Affected
Any cPanel account on an unpatched server can run code as root through the CalDAV and CardDAV service and take full control of the host.
Fix
Update cPanel and WHM to the fixed 11.134, 11.136, or 11.138 builds and WP Toolkit 6.11.3, then audit accounts and reset exposed logins.

Acronis cPanel backup plugin flaw exploited to escalate privileges on hosting servers

Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.

Check
Update the Acronis Backup plugin for cPanel and WHM to the fixed version immediately, and update the Plesk extension too, then review shared servers for signs of privilege escalation and unauthorized access.
Affected
Web hosts and managed service providers running the Acronis Backup plugin for cPanel and WHM (CVE-2026-87886); an attacker with a foothold can escalate privileges to reach backups, system files, and tenants' data.
Fix
Patch the backup plugin and extension, tighten file permissions and account isolation on shared hosting, monitor for privilege escalation and backup access, and treat a compromised hosting account as a server-wide risk.

LiteSpeed Enterprise flaw lets one hosting tenant gain root on a shared server

LiteSpeed disclosed that versions of its Enterprise web server before 6.3.7 contain a flaw that lets a low-privilege website user gain root access on the underlying server. On shared hosting, that means one tenant, reachable through a cheap plan or a stolen webmail login, can take over the whole machine and every other customer on it. Neither LiteSpeed nor cPanel has published how the flaw works, its severity, a CVE identifier, or whether it has been exploited, leaving defenders with little to hunt for. Because the update may be slow to arrive automatically, administrators are urged to install 6.3.7 manually. LiteSpeed's cPanel plugin had two similar exploited flaws earlier this year.

Check
Manually update LiteSpeed Enterprise to 6.3.7 now rather than waiting for auto-update, and on shared servers review tenant activity and privileges for signs of abuse given the missing technical details.
Affected
Shared-hosting providers and multi-tenant servers running LiteSpeed Enterprise before 6.3.7; a low-privilege website user can escalate to root and take over the entire server, exposing every other tenant's sites and data.
Fix
Install 6.3.7 manually across affected servers, isolate tenants, monitor for unexpected root processes and privilege escalation, rotate credentials on any suspected compromise, and treat shared hosting as one account from takeover.

New cPanel flaw lets a mail-privileged hosting account run code as root

cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.

Check
Update cPanel and WHM to the patched builds now, review which accounts hold mail-related privileges, and because no indicators were published, hunt broadly for unexpected root processes, files, and hidden accounts.
Affected
Shared-hosting providers and multi-tenant servers running unpatched cPanel and WHM (CVE-2026-67401); an authenticated account with mail privileges can inject SQL, create files, and execute code as root, taking over the entire machine.
Fix
Patch to the fixed builds, restrict mail-related privileges, isolate tenants, monitor for root-level file creation and command execution, rotate credentials on any suspected compromised server, and assume shared servers are one-account-from-root.

cPanel flaw lets a low-privilege hosting account seize root on the whole server

A critical flaw in cPanel and WHM, the dominant web hosting control panel, lets a low-privilege but authenticated account take root control of an entire server. Tracked as CVE-2026-65643, the bug lives in the domain-parking feature, which is enabled in virtually every shared and reseller hosting environment. Any account allowed to add parked or addon domains can create arbitrary files anywhere on the underlying server, leading to code execution as root. No advanced skills or chained bugs are needed, only a legitimate low-tier login obtainable through a cheap hosting plan or a compromised account. On shared hosting, one such account can compromise every site, database, and mailbox on the box.

Check
Apply cPanel's patched builds immediately, and while patching, review which accounts can add parked or addon domains and temporarily restrict that permission on unpatched servers.
Affected
Hosting providers and administrators running unpatched cPanel and WHM (CVE-2026-65643); an authenticated account with domain-parking permission can create files as root and take over the whole server, endangering every tenant on it.
Fix
Patch to a fixed cPanel build, confirm automatic updates applied, restrict domain-parking privileges meanwhile, monitor for unexpected files and root processes, and treat any compromised shared server as an incident.

Critical cPanel flaw lets a hosting customer gain database administrator access

cPanel patched a critical flaw that lets an ordinary hosting customer escalate to full database administrator access, running SQL as the database root user. Tracked as CVE-2026-58048 with a score of 9.4, the bug is significant on shared hosting, where many customers use one database server: administrator access there can expose or alter other tenants' data, and depending on the operating system and database configuration, cPanel warns it may extend to operating-system-level compromise. cPanel is one of the most widely deployed web hosting control panels, so the flaw affects a large number of shared and reseller hosting environments. Fixes shipped across several release tiers.

Check
Update cPanel to a patched build for your release tier, prioritizing shared and reseller servers, and if you host with a provider, confirm they have applied the fix.
Affected
Providers and customers on unpatched cPanel servers (CVE-2026-58048); a hosting customer can gain database root access, reaching other tenants' data and potentially the underlying operating system on shared infrastructure.
Fix
Apply cPanel's patched builds, apply the vendor's interim mitigation where immediate updating is not possible, review database accounts and logs for unauthorized administrator use, and segment tenants where feasible.

Exploited LiteSpeed cPanel plugin flaw lets hosting users gain root

CISA has added a LiteSpeed cPanel plugin flaw to its known-exploited list and given federal agencies until June 18 to patch. The bug (CVE-2026-54420, rated 8.5) lets a user who already has FTP or web-shell access on a shared hosting server escalate to root by abusing how the plugin follows symbolic links, on servers running CloudLinux or CageFS. On multi-tenant hosting that turns one compromised account into full control of the whole server and every site on it. Namecheap reported it after spotting suspicious activity, and LiteSpeed flagged active exploitation in early June. The fix is LiteSpeed WHM Plugin 5.3.2.1 with cPanel plugin 2.4.8.

Check
Identify shared-hosting servers running the LiteSpeed cPanel plugin on CloudLinux or CageFS, confirm the version, and review logs for unexpected privilege changes or suspicious command activity.
Affected
Shared hosting servers running the LiteSpeed cPanel user-end plugin before 2.4.8 on CloudLinux or CageFS (CVE-2026-54420); any account with FTP or web-shell access can escalate to root.
Fix
Upgrade to LiteSpeed WHM Plugin 5.3.2.1 (cPanel plugin 2.4.8) or later now. If you cannot patch immediately, remove the user-end plugin, then hunt for signs of prior root-level compromise.