support.cpanel.net
Critical cPanel SQL Injection Vulnerability Allows Root Code Execution
Article Content
cPanel has patched a critical SQL injection vulnerability (CVE-2026-67401) affecting its EmailTrack functionality. An authenticated user with mail privileges can exploit this flaw to create arbitrary files on the server, leading to code execution as the root user. This gives attackers full control over the server, impacting all supported versions of cPanel and WHM. The vulnerability was disclosed on September 8, 2026, but no public exploit code or confirmed exploitation has been reported yet. Administrators are urged to update to the latest patched version immediately, as the advisory does not provide interim mitigation steps. The flaw was responsibly disclosed by researchers Ali Mustafa and abed1526. cPanel's advisory lacks a severity score, but the potential impact is significant due to the access level gained by exploitation.
Key Points: • CVE-2026-67401 allows root access via SQL injection in EmailTrack. • All supported versions of cPanel and WHM are affected. • Immediate patching is required to prevent potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.