Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-67401: cPanel EmailTrack flaw lets attacker run code as root
CVE-2026-67401 · published 1 month ago
Summary
A flaw in cPanel’s EmailTrack feature lets a specially crafted email cause a database error that can be turned into code that runs with full system privileges. This could let an attacker take control of the entire server. Apply the latest cPanel update or patch that fixes the EmailTrack component as soon as possible.
What to do
- Update webpros cpanel to version 11.134.0.55 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | cpanel | < 11.134.0.55 |
Original advisory text
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-89SQL Injection
Timeline
Published9 Sep 2026
Updated7 Oct 2026
First seen9 Sep 2026
Track software like this
Free during beta