Cyber Security News

New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers.

cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a valid cPanel account with mail-related privileges to exploit the vulnerability.

While this requirement limits unauthenticated internet-wide exploitation, the potential impact remains severe for shared-hosting providers, managed servers, and organizations with multiple cPanel users.

CVE-2026-67401 is an SQL injection vulnerability in cPanel’s EmailTrack functionality. EmailTrack monitors and reviews email delivery activity, including message routing and delivery information.

A malicious authenticated user can abuse the vulnerable functionality to create arbitrary files on the underlying server. Arbitrary file creation is especially dangerous in a hosting environment because it can let attackers place controlled content in sensitive locations.

Cpanel Vulnerability

cPanel said successful exploitation can result in code execution as the root user. Root access provides unrestricted control over the operating system, allowing attackers to access hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.

An attacker with root-level access could also install persistence mechanisms, deploy malware, alter website content, steal customer data, turn off security tools, or use the compromised server to launch further attacks.

In multi-tenant hosting environments, compromising one privileged cPanel account could put other customers hosted on the same server at risk.

Security researcher Ali Mustafa, also known as (nd abe)1526, reported the vulnerability. The vulnerability affects all supported cPanel/WHM versions before the following patched builds:

cPanel/WHM ReleasePatched Version
cPanel & WHM 11.11011.110.0.143
cPanel & WHM 11.13411.134.0.55
cPanel & WHM 11.13611.136.0.39
cPanel & WHM 11.13811.138.0.4
WP2 release11.138.1.9

Server administrators should verify their installed cPanel/WHM version immediately and upgrade to a patched release. Organizations using managed hosting should also confirm with their provider that the update has been applied across all affected systems.

The primary mitigation is to update cPanel/WHM to the latest available patched version. Administrators should not rely only on restricting public access, because exploitation requires a legitimate authenticated account rather than anonymous access.

Security teams should review cPanel accounts with email-related permissions and remove unnecessary privileges. Enable passwords and multi-factor authentication for accounts that may have been exposed or are no longer required.

Administrators should also investigate for suspicious files, unexpected changes to web directories, modified configuration files, unusual root-level processes, and unexplained outbound network connections. Reviewing cPanel, web-server, authentication, and system logs may help identify exploitation attempts.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

26 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

10 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

11 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago