Shared hosting gaps can expose neighboring accounts and servers

Shared hosting gaps can expose neighboring accounts and servers. Shared-hosting customers can lose data isolation when one tenant is able to reach another tenant’s resources. cPanel has patched several flaws with different consequences.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 24th, 2026.

Shared-hosting customers can lose data isolation when one tenant is able to reach another tenant’s resources. cPanel has patched several flaws with different consequences. An authenticated account could potentially run code as root, read calendar and contact data belonging to other users, or modify databases owned by other accounts. The most serious issue could provide complete control of the underlying server.

cPanel released corrected builds, while the separately packaged WP Toolkit needs to be upgraded to version 6.11.3 or later. The business impact can extend well beyond one customer because a shared server may host many unrelated accounts. Even read-only access to schedules and contacts can expose business relationships and support convincing phishing. Leaders should treat any failure of tenant isolation as an urgent multi-customer incident. Defenders should prioritize public shared servers, verify installed versions, and review account, database, calendar, and address-book activity for unexplained access. The broader lesson is that low-privileged access becomes much more dangerous when many customers share one control plane. Patch both components, confirm every node’s version, and investigate cross-account activity.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Shared hosting gaps can expose neighboring accounts and servers
Broadcast by