# cPanel fixes flaw that could give hosting customers root access

_Published Wednesday, September 23, 2026 at 10:08 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![cPanel fixes flaw that could give hosting customers root access — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhT5quc0dmRWhh6WOC80Gx9QoHTMYyq5srnXBXjybOKZk_qoUn1Q2nKLE9MifqCEyRIha_NFvRsyr8Nx5EyxGIREXaTb5Fh59cz4Ln8yZj9Zv7piqM49wmm7rfmchW1cVlss1wn47qNypaYarZUVNHBO8rzXaYTvRMi9u1phgfXVd8OZx8_Vjxm34684BE/s1700-nu-rw-lo-l85-e365/cpanel-0day.jpg)

cPanel released a fix for a flaw in its calendar and contacts service that could let anyone with a hosting account run code as root and take control of a shared server, The Hacker News reported. The company also fixed a WP Toolkit flaw that could let one account modify another account's databases, and a separate flaw that could expose other accounts' calendar events and contacts.

The root-access flaw requires a cPanel account. None of the three advisories cited known exploitation, according to the report.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html)

---
Canonical: https://techandbusiness.org/newswire/edul74ewTQmMY9hzwG1akQ
Published: 2026-09-23T14:08:26.868Z
Story chronology: 2026-09-22T00:00:00.000Z
Retrieved: 2026-09-23T15:56:00.161Z
Publisher: Tech & Business (techandbusiness.org)
