CVE- 2026-67401 is a newly disclosed SQL injection flaw in cPanel that could allow an attacker to gain full control of a server. The advisory describes an authenticated cPanel account holder with mail-related privileges who can abuse cPanel’s Email Track functionality to create arbitrary files on the server by injecting malicious SQL. Exploitation could lead to code execution with root privileges, effectively giving the attacker complete control over the host. The report notes that, at present, there is no public proof-of-concept or evidence of active exploitation in the wild.
The vulnerability affects multiple releases of cPanel and WHM prior to the patched updates, including WP Squared deployments if they are not kept current. In response, system administrators are urged to apply the security patches immediately. The recommended mitigation is to update cPanel and WHM to the secured builds via the WHM dashboard or the command line; specifically, administrators can run /usr/local/cpanel/scripts/upcp –force to force an update.
The official cPanel security advisory provides detailed fixed builds, and the article lists versions to maintain as secure: v11.138.0.4 for cPanel and WP2 v11.138.1.9 for related deployments. As with other high‑risk flaws, the guidance emphasises timely patching to prevent potential data theft, service disruption, or broader compromises of shared hosting environments.