started · updated
cPanel patches critical vulnerability allowing root access via EmailTrack
cPanel has released patches for a critical security vulnerability, identified as CVE-2026-67401, which allows an authenticated user with mail-related privileges to gain full root access to a server.
The flaw stems from a SQL injection within the EmailTrack function, a feature used by hosting accounts to monitor the status and routing of outgoing emails. By exploiting this vulnerability, an attacker can create arbitrary files on the target system and subsequently execute code with root privileges. This effectively breaks the security boundary between individual customer accounts and the server management layer (WHM).
The vulnerability affects all supported versions of cPanel and WHM. Patches have been released across several release lines, including versions 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and 11.138.1.9 for WP Squared. While the advisory confirms the technical cause as a SQL injection, specific details regarding the exact permissions required or the precise mechanism used to escalate from file creation to root execution have not been fully disclosed.