SQL Injection Vulnerability in cPanel's EmailTrack Component
CVE-2026-67401

9.9CRITICAL

Key Information:

Vendor

Webpros

Status
Vendor
CVE Published:
9 September 2026

Badges

📰 News Worthy

What is CVE-2026-67401?

A vulnerability in cPanel's EmailTrack component enables mail-enabled accounts to execute remote code with root privileges through an SQL injection exploit. This security flaw allows unauthorized users to manipulate SQL queries, leading to potential system compromise and disruption of services. Such vulnerabilities necessitate immediate attention and remediation to protect sensitive data and ensure the integrity of your server environment.

Affected Version(s)

cPanel 0 < 11.134.0.55

cPanel 0 < 11.136.0.39

cPanel 0 < 11.138.0.4

News Articles

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.

10 hours ago

References

CVSS V3.0

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.