New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

General Security Talk, Announcements and News
Post Reply
Starburst-David
Posts: 314
Joined: Wed Feb 11, 2026 8:31 pm

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

Post by Starburst-David »

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.

cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

The flaw is tracked as CVE-2026-67401. cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel's developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not say whether that is the affected code.

Published Date: Sep 09, 2026

Full article at:
https://thehackernews.com/2026/09/new-c ... count.html
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “General”