New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server
cPanel disclosed critical SQL injection CVE-2026-67401 in EmailTrack, letting authenticated users with mail privileges gain root code execution; patched builds available.
cPanel disclosed CVE-2026-67401 on September 8, 2026, a critical SQL injection in the EmailTrack feature that monitors email delivery and routing. An authenticated attacker holding a valid cPanel account with mail-related privileges can create arbitrary files and achieve code execution as root, enabling full compromise of hosting servers and exposure of co-tenant customers. All supported cPanel/WHM versions before specific patched builds (11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9 WP2) are affected; upgrading is the primary mitigation. No exploitation was reported at disclosure.
- Exploitation requires an authenticated cPanel account with mail privileges.
- Root access exposes hosted sites, databases, backups and stored credentials.
- Multi-tenant hosting means one compromise can affect other customers.
- Patched builds issued across 11.110, 11.134, 11.136 and 11.138 branches.
- Admins advised to review mail-privileged accounts and hunt for suspicious files.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-67401 | Authenticated SQL Injection in cPanel EmailTrack Leads to Root RCE CVE-2026-67401 is a critical SQL injection (CWE-89) in the EmailTrack component of cPanel, the widely used hosting control panel. An attacker holding any mail-enabled account on the server can reach the vulnerable component over the network with low privileges and no user interaction (CVSS: AV:N/AC:L/PR:L/UI:N), and the injection crosses a privilege boundary (Scope: Changed) to achieve remote code execution as root. Successful exploitation yields full compromise of the host — arbitrary commands as root with complete access to all hosted data — so every site, mailbox and account on an affected server is exposed. All cPanel deployments with mail enabled are potentially affected; the available data does not specify exact vulnerable version ranges, which are provided in WebPros security advisory AV26-908. Exploitation has not been confirmed in the wild (not in CISA KEV), but two public proof-of-concept exploits are already on GitHub, making near-term exploitation likely. Do: Upgrade cPanel to the patched release identified in WebPros advisory AV26-908 (exact fixed version numbers are not given in the available data), prioritizing internet-facing servers that host mail-enabled accounts. Until patched, restrict access to the EmailTrack component and audit mail-enabled accounts and logs for suspicious database queries or unexpected root-level processes, since public PoC exploits are already available. | 9.9 | <1% | PoC ×3 |
| masstens of millions of hosted accounts across hundreds of thousands of cPanel servers |
Full article453 words · extracted from cybersecuritynews.com · click to collapse
cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers.
cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a valid cPanel account with mail-related privileges to exploit the vulnerability.
While this requirement limits unauthenticated internet-wide exploitation, the potential impact remains severe for shared-hosting providers, managed servers, and organizations with multiple cPanel users.
CVE-2026-67401 is an SQL injection vulnerability in cPanel’s EmailTrack functionality. EmailTrack monitors and reviews email delivery activity, including message routing and delivery information.
A malicious authenticated user can abuse the vulnerable functionality to create arbitrary files on the underlying server. Arbitrary file creation is especially dangerous in a hosting environment because it can let attackers place controlled content in sensitive locations.
Cpanel Vulnerability
cPanel said successful exploitation can result in code execution as the root user. Root access provides unrestricted control over the operating system, allowing attackers to access hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.
An attacker with root-level access could also install persistence mechanisms, deploy malware, alter website content, steal customer data, turn off security tools, or use the compromised server to launch further attacks.
In multi-tenant hosting environments, compromising one privileged cPanel account could put other customers hosted on the same server at risk.
Security researcher Ali Mustafa, also known as (nd abe)1526, reported the vulnerability. The vulnerability affects all supported cPanel/WHM versions before the following patched builds:
| cPanel/WHM Release | Patched Version |
|---|---|
| cPanel & WHM 11.110 | 11.110.0.143 |
| cPanel & WHM 11.134 | 11.134.0.55 |
| cPanel & WHM 11.136 | 11.136.0.39 |
| cPanel & WHM 11.138 | 11.138.0.4 |
| WP2 release | 11.138.1.9 |
Server administrators should verify their installed cPanel/WHM version immediately and upgrade to a patched release. Organizations using managed hosting should also confirm with their provider that the update has been applied across all affected systems.
The primary mitigation is to update cPanel/WHM to the latest available patched version. Administrators should not rely only on restricting public access, because exploitation requires a legitimate authenticated account rather than anonymous access.
Security teams should review cPanel accounts with email-related permissions and remove unnecessary privileges. Enable passwords and multi-factor authentication for accounts that may have been exposed or are no longer required.
Administrators should also investigate for suspicious files, unexpected changes to web directories, modified configuration files, unusual root-level processes, and unexplained outbound network connections. Reviewing cPanel, web-server, authentication, and system logs may help identify exploitation attempts.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/cpanel-sql-injection-vulnerability/