cPanel EmailTrack SQL Injection Vulnerability Grants Root Access

A serious SQL injection flaw, tracked as CVE-2026-67401, exists in cPanel & WHM's EmailTrack feature. The vulnerability was disclosed by cPanel on September 8, 2026. An attacker authenticated with a standard, mail-enabled cPanel account can exploit it to write arbitrary files to the server and achieve root-level code execution. This flaw could allow a single user on a shared hosting server to compromise the entire system.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in