importantSYS.SOURCE: The Hacker News• 2026-09-09T13:49:32+05:30
Critical cPanel Vulnerability Allows Privilege Escalation via EmailTrack Module
A critical cPanel vulnerability (CVE-2026-67401) allows authenticated accounts with mail privileges to execute arbitrary code as root through an SQL injection in the EmailTrack module. The flaw affects all supported cPanel/WHM versions and enables full server compromise if unpatched.
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.
cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
*** END OF TRANSMISSION ***