cPanel has patched a security flaw that could allow a single hosting account to take control of an entire server. The vulnerability affects accounts with certain mail-related privileges and can be abused through cPanel’s EmailTrack functionality to create attacker-controlled files and eventually execute code with root-level access.
Tracked as CVE-2026-67401, the vulnerability was disclosed by cPanel on September 8. The company says all supported versions of cPanel and WHM are affected.
cPanel describes the issue as an SQL injection vulnerability in EmailTrack, although its advisory does not specify exactly which feature or account privilege is required to exploit it. cPanel’s developer documentation describes EmailTrack as a module used to track email statistics, but the company has not confirmed whether that is the specific component involved in the vulnerability.
The problem is particularly serious because cPanel and WHM operate at different levels. Individual customers typically manage their hosting accounts through cPanel, while hosting providers use WHM to manage the entire server with root privileges. If an attacker manages to gain root access, they could potentially access other hosting accounts on the same machine, modify websites and databases, create hidden accounts, install malware, steal credentials, and potentially move deeper into customer networks.
This is not the first serious cPanel security issue this year. A separate vulnerability exploited in April allowed attackers to bypass authentication and take control of the panel. Security company Hadrian noted at the time that compromising the panel is much more serious than compromising a single customer’s website because WHM can provide administrative control over the entire server.
cPanel has released fixes for CVE-2026-67401 across several release lines. The fixed builds are 11.110.0.143 for the 11.110 branch, 11.134.0.55 for 11.134, 11.136.0.39 for 11.136, 11.138.0.4 for 11.138, and 11.138.1.9 for WP Squared.
Administrators can update cPanel through WHM by going to Home, then cPanel, and selecting Upgrade to Latest Version. cPanel also provides a command-line update method that requires logging in as root and running /usr/local/cpanel/scripts/upcp --force.
The company has not explained in its advisory exactly how the SQL injection vulnerability can be turned into file creation and then root-level code execution. It also does not provide a temporary mitigation for administrators who cannot immediately install the available updates.
That is different from some of cPanel’s previous advisories. For a database privilege escalation flaw disclosed on July 30, cPanel provided administrators who could not upgrade with a temporary option to remove the MySQL feature from affected cPanel users.
The latest fixed builds cover the 11.110, 11.134, 11.136 and 11.138 release lines. cPanel previously issued security fixes for the 11.118 and 11.126 branches in July but has not listed those branches in its more recent advisories or clarified whether they remain supported.
The vulnerability also does not currently have a published severity score. cPanel says its recent CVEs are assigned through HackerOne, with CVSS scores appearing in the CVE records rather than directly in the company’s security advisories.
When The Hacker News checked on September 9, there was no CVE record available for CVE-2026-67401 in the CVE Program’s record store. Searches also found no public exploit code or reports showing that the vulnerability had been exploited. The flaw was also not included in CISA’s Known Exploited Vulnerabilities catalog in the version released on September 8.
However, the absence of public exploitation reports does not prove that the vulnerability has not been abused. A separate cPanel authentication bypass from April is already listed in CISA’s catalog and has been linked to ransomware activity.
Two other cPanel vulnerabilities disclosed since late July have also started with access to an ordinary hosting account. One flaw disclosed on July 30 involved the database feature and could allow an account with database access to execute commands with full administrative privileges. Another vulnerability disclosed on August 27 involved domain parking and could ultimately lead to root-level code execution.
Repositories claiming to contain working exploits for those two vulnerabilities were also found online when they were checked on September 9.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
cPanel credited Ali Mustafa, known as rz1027, and abed1526 for reporting CVE-2026-67401. The company has not indicated that this vulnerability is related to the other recent cPanel flaws, and the available records classify the vulnerabilities differently.



