cPanel EmailTrack: authenticated file create to root (CVE-2026-67401)
cPanel's 8 September 2026 advisory is titled SQL injection in EmailTrack. The body says an authenticated account with mail-related privileges can create arbitrary files through EmailTrack, and that success is code execution as root. All supported versions. Patched builds: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and WP Squared 11.138.1.9. Credit to Ali Mustafa (rz1027) and abed1526. No CVSS and no exploitation claim on the vendor page. Separate from the August domain-parking flaw and from the April login bypass. THN (9 Sep) confirms no public exploit and absence from CISA KEV catalog version released 8 Sep; notes related July DB and August parking flaws have purported exploit repos online.
- Product
- cPanel/WHM EmailTrack, WP Squared
- Versions
- All supported versions before the 8 September patched builds
- Exploited in Australia?
- unknown
- Patch to
- 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or WP2 11.138.1.9 or later
Primary: cPanel advisory (8 Sep 2026) · Vendor: cPanel, CVE-2026-67401 · CVE: CVE-2026-67401 · The Hacker News (9 Sep 2026)
