CVE-2026-68490
published 2026-09-23CVE-2026-68490: Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
PriorityP434high8.2CVSS 4.0
AVLACLATNPRLUINVCHVINVANSCHSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.14%
2.6th percentile
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | >= 11.120.0.0 < 11.134.0.57 | 11.134.0.57 |
| webpros | cpanel | >= 11.136.0.0 < 11.136.0.41 | 11.136.0.41 |
| webpros | cpanel | >= 11.138.0.0 < 11.138.0.8 | 11.138.0.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WebPros cPanel prior 11.134.0.57/11.136.0.41/11.138.0.8 CalDAV/CardDAV permission
vuldb·2026-09-23·CVSS 8.2
CVE-2026-68490 [HIGH] WebPros cPanel prior 11.134.0.57/11.136.0.41/11.138.0.8 CalDAV/CardDAV permission
A vulnerability identified as problematic has been detected in WebPros cPanel. This issue affects some unknown processing of the component CalDAV/CardDAV. Performing a manipulation results in permission issues.
This vulnerability is known as CVE-2026-68490. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.
GHSA
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
ghsa_unreviewed·2026-09-23
CVE-2026-68490 [HIGH] CWE-732 Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
blogs_hackernews·2026-09-28·CVSS 9.8
CVE-2026-88771 [CRITICAL] ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.
Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore.
Here’s the full recap of what mattered this week.
## ⚡ Threat of the Week
Citrix
Hackernews
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
blogs_hackernews·2026-09-23
CVE-2026-87899 New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.
cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other a
2026-09-23
Published