Critical cPanel CVE-2024-XXXX Vulnerability Lets Attackers Gain Full Server Control
Key Takeaways cPanel has disclosed a critical SQL injection vulnerability, identified as CVE-2026-67401, within its EmailTrack feature. This flaw allows authenticated attackers with mail-related...
Key Takeaways
- cPanel has disclosed a critical SQL injection vulnerability, identified as CVE-2026-67401, within its EmailTrack feature.
- This flaw allows authenticated attackers with mail-related privileges to achieve root-level control over affected servers.
- The vulnerability poses a significant risk to shared-hosting environments and organizations utilizing multiple cPanel users.
- Patches are available across various cPanel & WHM versions, and immediate updates are strongly recommended.
Critical cPanel Vulnerability Grants Root Access
cPanel has recently announced the discovery of a critical SQL injection vulnerability, tracked as CVE-2026-67401, which resides in the EmailTrack functionality of its widely used web hosting control panel. This severe flaw could enable authenticated attackers to gain complete root-level control over vulnerable servers.
Table Of Content
The security issue was publicly disclosed by cPanel on September 8, 2026. Exploiting this vulnerability requires an attacker to possess a valid cPanel account with specific mail-related permissions. While this prerequisite limits the possibility of widespread, unauthenticated internet-based attacks, the potential ramifications for shared-hosting providers, managed server environments, and organizations managing numerous cPanel users remain exceptionally high.
Understanding the EmailTrack Flaw
CVE-2026-67401 specifically targets the EmailTrack feature, a component designed to monitor and review email delivery activities, including message routing and detailed delivery information. An authenticated user with malicious intent can leverage this vulnerability to create arbitrary files on the underlying server. In a hosting context, the ability to create arbitrary files is particularly dangerous, as it allows attackers to place their controlled content into sensitive system locations.
Impact of Successful Exploitation
cPanel said successful exploitation of this vulnerability can lead to arbitrary code execution with root privileges. Root access provides an attacker with unfettered command over the operating system, granting them the ability to access all hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.
With root-level access, an attacker could install persistent backdoors, deploy malware, modify website content, exfiltrate sensitive customer data, disable security tools, or even use the compromised server as a launchpad for further attacks. In multi-tenant hosting environments, the compromise of a single privileged cPanel account could expose other customers hosted on the same server to significant risk.
The vulnerability was reported by security researcher Ali Mustafa, known by the handle (nd abe)1526. The flaw impacts all supported cPanel/WHM versions preceding the patched builds listed below:
| cPanel/WHM Release | Patched Version |
|---|---|
| cPanel & WHM 11.110 | 11.110.0.143 |
| cPanel & WHM 11.134 | 11.134.0.55 |
| cPanel & WHM 11.136 | 11.136.0.39 |
| cPanel & WHM 11.138 | 11.138.0.4 |
| WP2 release | 11.138.1.9 |
What You Should Do
- Update Immediately: Server administrators must promptly verify their current cPanel/WHM version and upgrade to one of the officially patched releases. Organizations utilizing managed hosting services should contact their providers to confirm that the necessary updates have been applied across all relevant systems.
- Do Not Rely on Restricted Access Alone: Since exploitation requires an authenticated account, restricting public access is insufficient. The primary mitigation remains updating cPanel/WHM to the latest patched version.
- Review Account Privileges: Security teams should review all cPanel accounts with email-related permissions. Remove any unnecessary privileges from these accounts to reduce the attack surface.
- Enhance Authentication: Implement strong passwords and enable multi-factor authentication (MFA) for any accounts that may have been exposed or are no longer actively required.
- Monitor for Anomalies: Administrators should actively investigate for suspicious files, unexpected changes to web directories, modified configuration files, unusual root-level processes, and unexplained outbound network connections.
- Audit Logs: Regularly review cPanel, web-server, authentication, and system logs. This can help identify potential exploitation attempts or indicators of compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.