news.mlab.sh
Back to the feed
vulnerability

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

High
Summary

A new cPanel vulnerability (CVE-2026-67401) allows a hosting account with mail privileges to execute code as root, potentially compromising an entire server. This vulnerability, classified as an SQL injection, stems from a flaw in EmailTrack and could lead to widespread server takeover. While no public exploits have been found yet, similar vulnerabilities in the past have been leveraged in ransomware campaigns.

cPanel has patched a vulnerability that could allow a single hosting account to take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. The vulnerability is tracked as CVE-2026-67401 and is classified as an SQL injection issue in EmailTrack. cPanel’s developer documentation lists an EmailTrack module that tracks email statistics, but the advisory does not specify whether that is the affected code. cPanel is web hosting control panel software. A customer manages one hosting account via cPanel, while the provider manages the entire machine via WHM as the root user. Attackers exploited a different cPanel flaw in April, an authentication bypass, that didn’t require an account at all. Taking over the panel is not the same as breaking into one customer’s website, as WHM gives an attacker root administrative access to the server, allowing them to read every hosting account, change files and databases, create hidden accounts, install malware, steal credentials, and move into customer networks. cPanel credits Ali Mustafa (rz1027) and abed1526 with reporting this one. The CVE record for the August flaw credits the same name, Ali Mustafa. cPanel has released patched builds for versions 11.118, 11.126, 11.112.0.0 up to, but not including, 11.134.0.53. cPanel does not say whether installing the patched build helps a server that was attacked before the update, or how an administrator would check. The advisory carries no severity score, though the August flaw was assigned a CVSS score of 8.7, indicating high severity. No public exploit code or report of exploitation appeared in searches on September 9, and CVE-2026-67401 is absent from CISA's Known Exploited Vulnerabilities catalog in the version released on September 8.

Read the full article at The Hacker News