Threat Advisory

cPanel Flaw Grants Full Control of the Server

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-67401 is a critical SQL injection vulnerability in cPanel/WHM’s EmailTrack functionality, affecting supported cPanel versions. The flaw can be exploited by an authenticated cPanel account with appropriate mail-related privileges. Successful exploitation may allow attackers to create arbitrary files on the affected server. This could potentially be chained to achieve arbitrary code execution with root privileges. The vulnerability can therefore lead to complete server compromise and significant impact on confidentiality, integrity, and availability. The affected product is cPanel/WHM across supported versions.

RECOMMENDATION:

We recommend you to refer below link: https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-67401 is a critical SQL injection vulnerability in cPanel/WHM’s EmailTrack functionality, affecting supported cPanel versions. The flaw can be exploited by an authenticated cPanel account with appropriate mail-related privileges. Successful exploitation may allow attackers to create arbitrary files on the affected server. This could potentially be chained to achieve arbitrary code execution with root privileges. The vulnerability can therefore lead to complete server compromise and significant impact on confidentiality, integrity, and availability. The affected product is cPanel/WHM across supported versions.

RECOMMENDATION:

We recommend you to refer below link: https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu