SecurityUnverified

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,

What happened

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,

Why it matters

The launch may affect adoption and competitive positioning for Security; usage evidence is the next signal to watch.

Affected entities

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

Claims

  • New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude62
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency55
Ranking · formula rank-1.0.0
Confidence factor0.8425
Freshness factor0.996
Breaking bonus0
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control | IntelCap