Permission Assignment Flaw in cPanel Leading to Sensitive Data Exposure
CVE-2026-68490
8.2HIGH
What is CVE-2026-68490?
A vulnerability in cPanel's permission settings allows local users to access sensitive CalDAV and CardDAV information from other user accounts. This flaw stems from incorrect permission assignment, which can lead to unauthorized access to sensitive data, posing a significant risk to user privacy and security. Users should review their configurations and consider necessary updates to mitigate potential data exposure.
Affected Version(s)
cPanel 11.120.0.0 < 11.134.0.57
cPanel 11.136.0.0 < 11.136.0.41
cPanel 11.138.0.0 < 11.138.0.8
