cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.
CVE Dictionary Entry:
CVE-2026-67401
NVD Published Date:
Sep 09, 2026
More Details:
https://nvd.nist.gov/vuln/detail/cve-2026-67401
CVE-2026-67401 - A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root
-
Starburst-David
- Posts: 314
- Joined: Wed Feb 11, 2026 8:31 pm