cPanel disclosed and patched CVE-2026-67401 on September 8, a SQL injection vulnerability in its EmailTrack feature. According to the advisory, an authenticated hosting account holder with mail-related privileges could exploit the flaw to create arbitrary files on the server through EmailTrack, then use that file-creation capability to execute code as the root user, the highest level of system access. The flaw affected every supported release line of cPanel and WHM. cPanel published patched builds for each affected line, including 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9. Because exploitation requires only an authenticated mail-privileged account rather than any special administrative access, the flaw posed particular risk to shared-hosting providers and multi-tenant environments, where a single compromised customer account could have endangered every other customer on the same server. Researchers Ali Mustafa and abed1526 are credited with reporting the vulnerability. As of September 9, no public exploit code or evidence of active exploitation had been reported, and the flaw did not appear in CISA's Known Exploited Vulnerabilities catalog. B2B SaaS companies that rely on shared or reseller hosting for customer-facing infrastructure should confirm their hosting provider has applied the patched cPanel/WHM builds.
Global Cybersecurity and Data 11 Sept 2026
Critical cPanel Flaw Let Mail-Privileged Accounts Gain Root Access to Shared Servers
cPanel patched a critical SQL injection vulnerability, CVE-2026-67401, in its EmailTrack feature on September 8, which allowed any authenticated account with mail privileges to create files on the server and execute code as root, affecting every supported cPanel/WHM version.
Source: The Hacker News, September 9, 2026
Comments
0 commentsNo comments yet — be the first.