CVE-2026-67401: cPanel EmailTrack SQL Injection Leads to Root Takeover
A SQL injection flaw, CVE-2026-67401 (CWE-89), in cPanel & WHM's EmailTrack feature lets a standard mail-privileged account write arbitrary files and escalate to root via local privilege escalation. All supported versions 11.110–11.138 are affected; a patch was released September 8, 2026.
- CVE-2026-67401 (CWE-89) affects the EmailTrack feature in cPanel & WHM
- Exploitation needs only a standard account with mail privileges, not admin access
- SQL injection via INTO OUTFILE writes a file, then local escalation reaches root
- Affected versions include 11.110, 11.134, 11.136, 11.138 and the WP2 line
Read next
Security