cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take full control of affected servers. cPanel announced this issue on September 8, 2026. They say that an attacker needs a valid cPanel account with email rights to use this weakness.
This requirement stops unauthorized use of the internet, but it can still seriously affect shared-hosting providers, managed servers, and groups with many cPanel users. CVE-2026-67401 is a weakness in cPanel’s EmailTrack feature that allows SQL injection. EmailTrack checks and looks at email sending activities, like message paths and delivery details.
A bad user with access can misuse the weak system to make any files on the server. Creating any files is very risky in a hosting setup because it allows attackers to put harmful content in important places.
Cpanel Vulnerability
CPanel said that successful exploitation can lead to code running as the root user. Root access gives full control over the operating system. This allows attackers to reach hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.
An attacker with full access could install methods to stay hidden, add bad software, change website content, steal customer information, disable security tools, or use the hacked server to attack again.
Compromising one special cPanel account in shared hosting could endanger other customers on the same server. Security expert Ali Mustafa, known as (nd abe)1526, found the weakness. This weakness impacts all cPanel/WHM versions that are still supported before the fixed builds:
| cPanel/WHM Release | Patched Version |
|---|---|
| cPanel & WHM 11.110 | 11.110.0.143 |
| cPanel & WHM 11.134 | 11.134.0.55 |
| cPanel & WHM 11.136 | 11.136.0.39 |
| cPanel & WHM 11.138 | 11.138.0.4 |
| WP2 release | 11.138.1.9 |
Server admins need to check their cPanel/WHM version right away and upgrade to a fixed release. Groups using managed hosting should also ask their provider to make sure the update is done on all affected systems.
The most important fix is to update cPanel/WHM to the newest patched version. Admins should not just limit public access because attacks need a real logged-in account, not anonymous access.
Security teams should check cPanel accounts that have email permissions and take away unneeded access. Turn on passwords and multi-factor authentication for accounts that might be unsafe or are not needed anymore.
Administrators should look for strange files, unexpected changes to web folders, changed settings files, odd root processes, and unknown outgoing network connections. Checking cPanel, web-server, login, and system logs may help find signs of exploitation attempts.
InfoSecBulletin Cybersecurity for mankind
