chiprook
← Security
SecurityOctober 2, 2026, 08:23

CVE-2026-67401: cPanel EmailTrack SQL Injection Leads to Root Takeover

A SQL injection flaw, CVE-2026-67401 (CWE-89), in cPanel & WHM's EmailTrack feature lets a standard mail-privileged account write arbitrary files and escalate to root via local privilege escalation. All supported versions 11.110–11.138 are affected; a patch was released September 8, 2026.

CVE-2026-67401: cPanel EmailTrack SQL Injection Leads to Root Takeover
#CPanel
Read next
Security

CVE-2026-76461: SQL injection in Cisco email gateway grants root

Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution

Security

cPanel flaw lets a hosting account run code as root and take over the server

Security

LiteSpeed Enterprise Bug Allows Root Access from Single Tenant