SECURITY·중요도 8·2026. 09. 23.·The Hacker News

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

── KO ──────────────────

cPanel의 취약점으로 사용자가 루트 권한으로 서버를 제어할 수 있는 문제가 발견되었습니다.

cPanel의 CalDAV 및 CardDAV 서비스에서 취약점이 발견되어, cPanel 호스팅 계정을 가진 사용자가 루트 권한으로 코드를 실행하고 서버의 전반적인 제어를 가질 수 있게 되었다고 합니다. 또한, WP Toolkit 플러그인에서 다른 계정의 데이터베이스를 변경할 수 있는 두 번째 취약점도 존재합니다. cPanel은 이 두 가지 문제를 해결하기 위한 패치된 버전을 출시했습니다.


── EN ──────────────────

A cPanel flaw allows account holders to run code as root, gaining full server control.

A flaw in cPanel's CalDAV and CardDAV service allows anyone with a cPanel hosting account to execute code as root and take full control of the server. A second bug in the WP Toolkit plugin enables account holders to modify databases belonging to other accounts. cPanel has released patched versions to address these issues.

원문 보기 →목록으로