Build1 publisher2 min readPublished
cPanel's EmailTrack SQL injection reaches root from an ordinary mail account
CVE-2026-67401 lets an ordinary cPanel mail account escalate to root through a SQL injection in the EmailTrack delivery-log feature. cPanel disclosed the vulnerability class but has not published the vulnerable parameter or the query behind it.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- EmailTrack is cPanel's Track Delivery feature, a read-only view of a user's own mail delivery logs that is scoped to that one account.
- cPanel's permission model keeps an ordinary account inside its own mail and domains and reserves control of the whole server for root through WHM.
- No second bug is needed to begin: a customer holding one ordinary cPanel mail account is already positioned to send the malicious request.
- The step-by-step exploit chain in circulation is a third-party conceptual reconstruction from the disclosed vulnerability class, not a cPanel-verified exploit.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure On a shared-hosting box every tenant sits behind the weakest neighbour: one compromised ordinary account can take the whole server, including accounts that did nothing wrong.
- constraint Without the parameter or the query in the open, operators cannot build a precise detection rule or confirm a workaround, so the vendor patch is the only reliable mitigation.
- decision Deferring the patch until a proof-of-concept lands treats exploitability as unknown, but the disclosed class already describes an unprivileged-mail-account-to-root path.
The injection the author describes sits in the request EmailTrack already handles for a logged-in user. In that reconstruction, a parameter the endpoint accepts, such as the account name, is concatenated into a SQL query unescaped, so the attacker, not the application, decides what SQL runs [8]. The tenant boundary was only ever enforced by one assumption, that the code never trusts user input, and the moment the account name reaches the query as code rather than as a value, application logic no longer enforces it [16].
The clause that turns a read into a write is INTO OUTFILE. MySQL and MariaDB support SELECT ... INTO OUTFILE for exports and backups, writing a query's result straight to the filesystem [15]. Injected into a query the attacker controls, it drops a file wherever the database process can write, usually the web root [9]. A PHP file there is interpreted on the next request and runs commands at the service account's privilege, not yet root [10]. Closing the last gap to root depends on a separate local escalation already present on the box, a SUID binary or a cron job or a task queue [11]. That makes five steps [1].
cPanel is closed-source, so none of this comes from its code [14]. The parameter name and the exact query, if public, would mostly help an attacker find the injectable field faster. This writeup does not list affected versions or a fixed release, so the upgrade target has to come from cPanel's advisory [5].
What to watch
- A CVSS score or exploitability rating from a numbering authority would sharpen how urgently to patch.
- A verified proof-of-concept would confirm the file-write-to-root chain the dev.to author only reconstructed.
- Reports of exploitation on live shared-hosting providers would move this from reconstructed to active.