cPanel has addressed a critical security vulnerability that exposed servers to potential takeover by a single hosting account with mail privileges. This flaw, identified as CVE-2026-67401, allowed authenticated users to create files on the server via the EmailTrack function, enabling them to execute code with root privileges. The vulnerability affected all supported versions of cPanel and WHM, as noted in cPanel’s advisory released on September 8.
The issue has been classified as an SQL injection vulnerability within the EmailTrack module. However, the advisory did not specify which specific feature or privilege was required to exploit the flaw. cPanel is widely used as a web hosting control panel, allowing individual customers to manage their hosting accounts while providers manage the entire server through WHM with root access.
The potential impact of this vulnerability was significant. An attacker with root access can read, modify, or delete any hosting account data on the server, create hidden accounts, install malware, and potentially pivot into customer networks, posing a severe security risk.
cPanel has released patched versions for multiple release lines, including 110, 134, 136, and 138. Administrators can update their servers using WHM or by executing a command line script. Despite the patch, the advisory does not provide guidance for servers that cannot be updated immediately, unlike previous advisories which offered temporary mitigation steps.
While no public exploit code or reports of exploitation were found at the time of the advisory, the vulnerability's severity underscores the need for prompt action. The CVE record for a related August flaw scored high on the CVSS scale, reflecting the critical nature of such vulnerabilities.
Security researchers Ali Mustafa and abed1526 were credited for reporting this flaw. The incident highlights the critical importance of promptly addressing vulnerabilities to maintain system integrity and security.

