cPanel Flaw Leaps From Mail Privileges to Root

cPanel patched CVE-2026-67401 on September 8 after saying an authenticated hosting account with mail-related privileges could abuse EmailTrack to create files on the server and run code as root. The issue affects every supported cPanel and WHM release line. In plain terms, a customer-level mail feature could be used to make the control panel write an attacker-chosen file, then turn that write into root execution. cPanel describes the flaw as an SQL injection problem in EmailTrack, but does not spell out the exact chain from injection to file creation and root access. For shared hosting operators, the exposure is not just one tenant site: once the panel boundary is crossed, the whole server is in scope, including other hosted accounts, databases, and credentials. That makes the blast radius machine-wide wherever mail privileges are granted on cPanel or WHM.

Part of the PlainSec briefing for 2026-09-09

Editions

Sources