CVE-2026-67401: cPanel says an authenticated hosting account with mail-related privileges can create files on a server through EmailTrack and, from there, run code as the root user.
What cPanel published on September 8
cPanel published an advisory on September 8 saying every supported version of cPanel and WHM is affected by CVE-2026-67401. The advisory calls the problem an SQL injection issue in EmailTrack and says an authenticated account holder with mail-related privileges can create files of their choosing on the server and then run code as root. The advisory does not say which specific cPanel feature or privilege an account needs to exploit the issue, and it does not explain how an SQL injection leads to file creation and escalation to root.
Technical surface described in the advisory
The vendor documentation lists an EmailTrack module that tracks email statistics; cPanel’s advisory names EmailTrack but does not confirm whether the documented module is the affected code. cPanel’s advisory also carries no severity score in the bulletin itself; recent cPanel CVEs have had their scores published through HackerOne and appear in the CVE Program record rather than inside cPanel advisories.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogWhy root access to WHM matters
cPanel emphasizes the distinction between taking over a single hosting panel and taking over the WHM-managed server. A WHM compromise grants root administrative access to the machine and, according to cPanel and reporting cited in the advisory, allows an attacker to read every hosting account on the server, change files and databases, create hidden accounts, install malware, steal credentials, and move into customer networks. The advisory recalls a precedent: an April cPanel flaw that required no account at all and was later included in a catalog of vulnerabilities tied to ransomware campaigns.
Patches, version lines, and update instructions
cPanel named fixed builds for the affected release lines and said a server can be updated from WHM under Home / cPanel / Upgrade to Latest Version. The vendor’s command-line instruction is to log in as root and run /usr/local/cpanel/scripts/upcp --force. The patched list covers the 110, 134, 136 and 138 release lines. cPanel previously patched the 11.118 and 11.126 lines in July advisories, has not listed them since, and has not said whether those lines remain supported.
The advisory offers no temporary mitigation steps for administrators who cannot immediately update. By contrast, in a July 30 advisory for a different database flaw, cPanel suggested a temporary mitigation — removing the MySQL feature from cPanel users — but no comparable interim action is given in the CVE-2026-67401 advisory.
Disclosure, exploit status, and researcher credits
When The Hacker News checked the CVE Program’s record store on September 9, no CVE Program record had been published for CVE-2026-67401. No public exploit code or report of exploitation appeared in searches on September 9, and CVE-2026-67401 was absent from CISA’s Known Exploited Vulnerabilities catalog in the version released on September 8. The absence of a public exploit or a CVE record as of September 9 does not in itself rule out exploitation.
By way of comparison, the August flaw referenced in the advisory had its CVE record published on September 1, five days after that advisory, and received a CVSS score of 8.7. Two other cPanel flaws disclosed since the end of July start from an ordinary hosting account: a July 30 database flaw that could let an account run database commands with full administrative privileges, and an August 27 domain-parking flaw that also led to code execution as root. Repositories presenting themselves as working exploits for those July and August flaws were online when The Hacker News checked on September 9.
cPanel credits Ali Mustafa (rz1027) and abed1526 with reporting CVE-2026-67401; the CVE record for the August flaw also credits Ali Mustafa.
What this means for hosting administrators, hosting providers, and customers
- Hosting administrators and security teams: cPanel provides an immediate update path in WHM and a root command-line upgrade. Administrators who cannot apply the update immediately lack a cPanel-provided temporary mitigation in this advisory, and the vendor has not said whether installing the patched build will remediate a server already attacked or how to verify a prior compromise.
- Hosting providers and platform owners: a single authenticated hosting account with mail-related privileges is described as sufficient to reach root; providers must weigh rapid patching against service-management constraints across release lines, including uncertainty about the 11.118 and 11.126 lines.
- Customers and website owners: cPanel’s advisory highlights the risk that a server-level compromise can expose every hosting account, databases and credentials on the machine — an elevated threat model compared with the compromise of a single customer site.
cPanel has issued patches and an update path; the advisory leaves administrators with a clear operational task — apply the update via WHM or the vendor command — and several open questions: which precise EmailTrack code path is affected, how the SQL injection becomes file-creation and root execution, and how administrators can detect or remediate an attack that occurred before patching. The vendor’s published instructions and the credited researchers are on the record; the community will be watching for technical details and CVE Program entries to follow.




