Vulnerability
Published 2026-09-08
Verified 2026-09-19

cPanel EmailTrack: authenticated file create to root (CVE-2026-67401)

cPanel's 8 September 2026 advisory is titled SQL injection in EmailTrack. The body says an authenticated account with mail-related privileges can create arbitrary files through EmailTrack, and that success is code execution as root. All supported versions. Patched builds: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and WP Squared 11.138.1.9. Credit to Ali Mustafa (rz1027) and abed1526. No CVSS and no exploitation claim on the vendor page. Separate from the August domain-parking flaw and from the April login bypass. THN (9 Sep) confirms no public exploit and absence from CISA KEV catalog version released 8 Sep; notes related July DB and August parking flaws have purported exploit repos online.

Product
cPanel/WHM EmailTrack, WP Squared
Versions
All supported versions before the 8 September patched builds
Exploited in Australia?
unknown
Patch to
11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or WP2 11.138.1.9 or later

Primary: cPanel advisory (8 Sep 2026) · Vendor: cPanel, CVE-2026-67401 · CVE: CVE-2026-67401 · The Hacker News (9 Sep 2026)

vulnerabilities cloud