thehackernews.com 9 Sept 2026, 08:19 UTC

Critical cPanel flaw lets email users escalate to root access

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A new cPanel vulnerability, tracked as CVE-2026-67401, could allow an authenticated hosting account with mail privileges to escalate to full root on the server. The flaw is described by cPanel as an SQL injection in the EmailTrack functionality, through which an attacker can create files on the server and then execute code with root privileges. The advisory was published on 8 September 2026, and cPanel states that every supported version of cPanel and WHM is affected.

Evidence in the article notes a high CVSS score (8.7) for the August advisory, and that no public exploit or exploitation report had been seen by 9 September 2026, with the CVE not yet listed in the Known Exploited Vulnerabilities catalog at that time.

The patched builds to mitigate the issue are listed for several release lines: 11.110 (11.110.0[.]143), 11.134 (11.134.0[.]55), 11.136 (11.136.0[.]39), 11.138 (11.138.0[.]4), and WP Squared (11.138.1[.]9). Administrators are advised to apply updates from WHM via Home / cPanel / Upgrade to Latest Version, or on the command line by running /usr/local/cpanel/scripts/upcp --force as root.

The advisory also notes ambiguity about which specific cPanel feature or privilege is required, and it does not outline interim steps beyond updating, unlike earlier advisories. In context, this remains a significant escalation risk because compromising WHM could grant an attacker root access to all hosted accounts.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline