Critical cPanel SQL Injection Vulnerability Allows Root Code Execution

Critical cPanel SQL Injection Vulnerability Allows Root Code Execution

First seen 9 Sep 2026, 09:42 UTC ThehackernewsCybersecuritynewssupport.cpanel.net 70.5

Article Content

Browse articles
ThreatCluster

cPanel has patched a critical SQL injection vulnerability (CVE-2026-67401) affecting its EmailTrack functionality. An authenticated user with mail privileges can exploit this flaw to create arbitrary files on the server, leading to code execution as the root user. This gives attackers full control over the server, impacting all supported versions of cPanel and WHM. The vulnerability was disclosed on September 8, 2026, but no public exploit code or confirmed exploitation has been reported yet. Administrators are urged to update to the latest patched version immediately, as the advisory does not provide interim mitigation steps. The flaw was responsibly disclosed by researchers Ali Mustafa and abed1526. cPanel's advisory lacks a severity score, but the potential impact is significant due to the access level gained by exploitation.

Key Points: • CVE-2026-67401 allows root access via SQL injection in EmailTrack. • All supported versions of cPanel and WHM are affected. • Immediate patching is required to prevent potential exploitation.

Ask AI about this cluster

Timeline

2026-09-08
cPanel discloses CVE-2026-67401
cPanel announced a critical SQL injection vulnerability affecting EmailTrack functionality, allowing root code execution.
support.cpanel.net
2026-09-09
Patch released for cPanel
cPanel released patched versions to address the SQL injection vulnerability, urging users to update immediately.
Thehackernews