Skip to content

Security1 publisher2 min readPublished

cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root

cPanel says every supported build of cPanel and WHM is affected by CVE-2026-67401, and its September 8 advisory arrived without a severity score or any interim step for hosts that cannot take the upgrade yet.

The Watch · Security desk

Illustration accompanying cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root

What happened

  • cPanel's September 8 advisory says an authenticated account holder with mail-related privileges can create files of its choosing through EmailTrack and then run code as root, on every supported cPanel and WHM version.
  • Fixed builds cover the 110, 134, 136 and 138 release lines, while the 11.118 and 11.126 lines were last patched in July and cPanel has not said since whether they remain supported.
  • The advisory ships no severity score, and The Hacker News found no CVE record for CVE-2026-67401 in the CVE Program's store when it checked on September 9.
  • The same checks on September 9 turned up no public exploit code and no report of exploitation, and the bug is absent from the KEV catalog version CISA released on September 8.
  • Repositories advertising working exploits for the two earlier tenant-to-root cPanel flaws, from July 30 and August 27, were online on September 9.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Root through WHM means one weak mail-enabled tenant exposes every other account on the box: files, databases, credentials, and routes into those customers' own networks.
  • constraint With no interim step published, hosts that batch maintenance have no lever between disclosure and the upgrade window, unlike July 30 when cPanel told them they could pull the MySQL feature from users.
  • decision Anyone still on 11.118 or 11.126 has to decide whether to move release lines without confirmation, since the August CVE record already listed no fixed build in either.
  • precedent April's account-free cPanel bypass ended up in KEV with ransomware use, which is the track record this software has once someone works out the chain.

The precondition is the part cPanel left blank. The advisory names EmailTrack and calls the bug SQL injection, without saying which feature or privilege an account needs [3]. cPanel's developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not confirm that is the affected code [4]. On a shared machine that forecloses triage by account: there is no published criterion for sorting the tenants who can reach the code from the ones who cannot, and the reported starting point is an authenticated account holder with mail-related privileges [2].

How the injection becomes file creation of the attacker's choosing, and then code as root, is also unwritten [5]. That costs detection more than it costs patching. There is no query, path or artifact to hunt for, and cPanel does not say whether installing the patched build helps a server attacked before the upgrade, or how an administrator would check [10]. The upgrade closes the entry point, but it does not answer whether a server was already occupied before the patch went in.

Whatever number eventually attaches to this will come through HackerOne into the CVE record rather than the advisory, which carries no score [11]. The record for the August flaw was published on September 1, five days after that advisory, at 8.7 on the CVSS scale [12]. On the same lag, a score for CVE-2026-67401 lands near September 13 [26]. Scheduling the upgrade does not depend on it.

Three cPanel flaws in the 40 days from July 30 to September 8 now begin inside an ordinary hosting account [25]. The July 30 advisory covered a database flaw that let an account with access to the database feature run database commands with full administrative privileges [17]. The August 27 flaw, in domain parking, ended where this one does, at code execution as root [18]. cPanel credits Ali Mustafa (rz1027) and abed1526 for reporting this one, and the CVE record for the August flaw credits the same Ali Mustafa [20]. Neither cPanel nor that record ties the two to the same code, and the classifications differ: eval injection in August, SQL injection here [21]. One researcher working a surface is a separate fact from one bug found in it.

The absence of public exploit code and exploitation reports on September 9 does not rule exploitation out, and The Hacker News said as much [15]. Servers update from WHM under Home / cPanel / Upgrade to Latest Version, or as root with /usr/local/cpanel/scripts/upcp --force [24]. For anyone who stages upgrades across a fleet, that window is the whole of the mitigation.

What to watch

  • A CVE record with a CVSS score for CVE-2026-67401 landing in the CVE Program store.
  • Public proof-of-concept code for the EmailTrack path, or a KEV listing for CVE-2026-67401.
  • cPanel confirming whether the 11.118 and 11.126 release lines are still supported.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories