Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-67401: cPanel EmailTrack flaw lets attacker run code as root

CVE-2026-67401 · published 1 month ago
Summary

A flaw in cPanel’s EmailTrack feature lets a specially crafted email cause a database error that can be turned into code that runs with full system privileges. This could let an attacker take control of the entire server. Apply the latest cPanel update or patch that fixes the EmailTrack component as soon as possible.

What to do
  • Update webpros cpanel to version 11.134.0.55 or later.
Affected software
VendorProductAffected versions
webpros cpanel < 11.134.0.55
Original advisory text
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published9 Sep 2026
Updated7 Oct 2026
First seen9 Sep 2026
Sources
CVE-2026-67401 · MITRE
Track software like this
Free during beta