ZeroHour
GBHackerspublished ()ingested Divya
Part of a story covered by 6 sources: “cPanel EmailTrack SQL Injection (CVE-2026-67401) Lets Mail-Privileged Accounts Run Code as Root; ConfigServer Firewall Flaw (CVE-2026-65638) Detailed, Patched in CSF 16.30” — merged summary and timeline →

cPanel EmailTrack SQL Injection Flaw Lets Attackers Execute Code as Root

AI summary · glm-5.3-flash

cPanel disclosed CVE-2026-67401, an authenticated SQL injection in EmailTrack that lets attackers write files and execute code as root.

cPanel disclosed CVE-2026-67401 on September 8, 2026: a SQL injection in the EmailTrack feature that allows authenticated account holders with mail-related permissions to create arbitrary files and execute code with root privileges. Fixes shipped in v11.110.0.143, v11.134.0.55, v11.136.0.39, v11.138.0.4, and WP2 channel v11.138.1.9, with all supported versions before those releases affected. Root-level execution poses severe risk to shared hosting providers and multi-tenant servers, as it removes isolation between cPanel accounts, websites, mailboxes, and backups. Researchers Ali Mustafa (rz1027) and abed1526 responsibly reported the flaw.

  • Authenticated cPanel accounts with mail permissions can escalate to root via arbitrary file writes.
  • All supported cPanel/WHM versions before the listed patched releases are affected.
  • Advises immediate patching, auditing mail privileges, credential rotation, and file integrity monitoring.
  • Treat suspicious low-privilege cPanel logins as potential full-server compromise until investigated.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-67401
Authenticated SQL Injection in cPanel EmailTrack Leads to Root RCE

CVE-2026-67401 is a critical SQL injection (CWE-89) in the EmailTrack component of cPanel, the widely used hosting control panel. An attacker holding any mail-enabled account on the server can reach the vulnerable component over the network with low privileges and no user interaction (CVSS: AV:N/AC:L/PR:L/UI:N), and the injection crosses a privilege boundary (Scope: Changed) to achieve remote code execution as root. Successful exploitation yields full compromise of the host — arbitrary commands as root with complete access to all hosted data — so every site, mailbox and account on an affected server is exposed. All cPanel deployments with mail enabled are potentially affected; the available data does not specify exact vulnerable version ranges, which are provided in WebPros security advisory AV26-908. Exploitation has not been confirmed in the wild (not in CISA KEV), but two public proof-of-concept exploits are already on GitHub, making near-term exploitation likely.

Do: Upgrade cPanel to the patched release identified in WebPros advisory AV26-908 (exact fixed version numbers are not given in the available data), prioritizing internet-facing servers that host mail-enabled accounts. Until patched, restrict access to the EmailTrack component and audit mail-enabled accounts and logs for suspicious database queries or unexpected root-level processes, since public PoC exploits are already available.

9.9<1% PoC ×3
  • cPanel (WebPros) cPanel
masstens of millions of hosted accounts across hundreds of thousands of cPanel servers
Full article465 words · extracted from gbhackers.com · click to collapse

cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to create arbitrary files on a server, which can ultimately enable them to execute code with root privileges.

The issue, published on September 8, 2026, affects all supported cPanel/WHM release versions before their respective fixes.

Because root-level execution can give attackers complete control of the host, this vulnerability poses a severe risk to shared hosting providers, enterprises that run multi-tenant servers, and administrators who delegate mail management through their cPanel accounts.

Although attackers do not need an unauthenticated foothold, they must have valid cPanel credentials with mail-related permissions.

cPanel EmailTrack SQL Injection Flaw

EmailTrack records and displays mail delivery tracking data, making this functionality especially relevant in scenarios where end users or reseller accounts can access email tools.

According to the advisory, the vulnerability allows for file creation as well as reading or modifying database content. This means attackers could potentially manipulate backend queries to reach privileged file-handling operations.

Once an attacker can write arbitrary files in a suitable location, they could deploy a malicious payload, configuration changes, or scripts to gain command execution.

The resulting process runs with root privileges, eliminating the usual operating system boundaries between the compromised cPanel account and other accounts, websites, mailboxes, sensitive information, backups, and server configurations.

cPanel has released fixes in versions v11.110.0.143, v11.134.0.55, v11.136.0.39, and v11.138.0.4, while the WP2 channel has received the correction in version v11.138.1.9.

Administrators should update immediately to the latest patched version available for their deployment instead of waiting for routine maintenance windows.

They should also review which accounts have mail-related privileges, disable unnecessary access, rotate credentials where compromise is suspected, and examine recent EmailTrack activity.

Additionally, implementing file integrity monitoring, web shell scanning, and inspecting root-owned or unexpectedly modified files can help identify signs of post-exploitation.

Hosting providers should treat any suspicious low-privilege cPanel login as a potential full-server compromise until a forensic review confirms otherwise.

Organizations should prioritize securing internet-facing systems and servers with many delegated users, as the authentication requirement does not significantly reduce risk after credential theft, phishing, password reuse, or reseller account compromises.

Security teams should preserve relevant logs before upgrades, correlate account logins with file-write events, and investigate unusual database errors or mail-tracking requests.

Researchers Ali Mustafa (rz1027) and abed1526 received acknowledgment for responsibly reporting the vulnerability. Prompt patching and strong credential hygiene remain the most effective defenses against a flaw that can turn limited panel access into a full infrastructure takeover.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/cpanel-emailtrack-sql-injection-flaw/