cPanel: New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

cPanel: New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

Critical SQL Injection Flaw in cPanel’s EmailTrack Grants Root Access (CVE-2026-67401)

On September 8, 2026, cPanel disclosed CVE-2026-67401, a critical SQL injection vulnerability in its EmailTrack feature, which could allow authenticated attackers to gain root-level control of vulnerable servers. The flaw affects all supported cPanel/WHM versions prior to patched releases, including 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and 11.138.1.9.

Exploitation requires a valid cPanel account with mail-related privileges, limiting the attack surface to authenticated users rather than unauthenticated internet-wide threats. However, the impact remains severe, particularly for shared-hosting providers, managed servers, and multi-tenant environments, where a single compromised account could endanger other customers on the same server.

The vulnerability stems from an SQL injection flaw in EmailTrack, a tool that monitors email delivery activity. Attackers can abuse this weakness to create arbitrary files on the server, enabling them to place malicious content in sensitive locations. Successful exploitation grants root access, providing full control over the system including hosted websites, databases, email accounts, backups, configuration files, and stored credentials.

With root privileges, attackers could:

  • Deploy malware or persistence mechanisms
  • Alter website content or steal customer data
  • Disable security tools
  • Use the compromised server as a launchpad for further attacks

Security researcher Ali Mustafa (nd abe1526) reported the flaw. cPanel has released patches for affected versions, and administrators are urged to upgrade immediately. While restricting public access is insufficient (since exploitation requires authenticated access), security teams should also:

  • Review cPanel accounts with email-related permissions and remove unnecessary privileges
  • Enforce multi-factor authentication (MFA) for exposed accounts
  • Monitor for suspicious files, unexpected changes, or unusual root-level processes
  • Analyze logs for signs of exploitation attempts

The vulnerability underscores the risks of privilege escalation in multi-user hosting environments, where a single compromised account can lead to a full server takeover.

Source: https://cybersecuritynews.com/cpanel-sql-injection-vulnerability/

cPanel TPRM report: https://www.rankiteo.com/company/cpanel

"id": "cpa1788949718",
"linkid": "cpanel",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Shared-hosting providers, '
                                              'managed servers, multi-tenant '
                                              'environments',
                        'industry': 'Web Hosting Control Panel',
                        'name': 'cPanel',
                        'type': 'Software Provider'}],
 'attack_vector': 'Authenticated access with mail-related privileges',
 'customer_advisories': 'Public disclosure and advisory urging immediate '
                        'upgrades and security measures',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, credentials, customer '
                                        'data)',
                 'type_of_data_compromised': ['Hosted websites',
                                              'Databases',
                                              'Email accounts',
                                              'Backups',
                                              'Configuration files',
                                              'Stored credentials']},
 'date_publicly_disclosed': '2026-09-08',
 'description': 'On September 8, 2026, cPanel disclosed CVE-2026-67401, a '
                'critical SQL injection vulnerability in its EmailTrack '
                'feature, which could allow authenticated attackers to gain '
                'root-level control of vulnerable servers. The flaw affects '
                'all supported cPanel/WHM versions prior to patched releases, '
                'including 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, '
                'and 11.138.1.9. Exploitation requires a valid cPanel account '
                'with mail-related privileges, enabling attackers to create '
                'arbitrary files and gain root access, leading to full system '
                'compromise.',
 'impact': {'data_compromised': 'Hosted websites, databases, email accounts, '
                                'backups, configuration files, stored '
                                'credentials',
            'identity_theft_risk': 'High (due to access to stored credentials '
                                   'and customer data)',
            'operational_impact': 'Full system compromise, potential malware '
                                  'deployment, security tool disablement, '
                                  'further attack launchpad',
            'systems_affected': 'cPanel/WHM servers (versions prior to '
                                '11.110.0.143, 11.134.0.55, 11.136.0.39, '
                                '11.138.0.4, 11.138.1.9)'},
 'lessons_learned': 'The vulnerability underscores the risks of privilege '
                    'escalation in multi-user hosting environments, where a '
                    'single compromised account can lead to a full server '
                    'takeover.',
 'post_incident_analysis': {'corrective_actions': 'Patches released to fix the '
                                                  'SQL injection vulnerability',
                            'root_causes': 'SQL injection flaw in EmailTrack '
                                           'feature due to improper input '
                                           'validation'},
 'recommendations': ['Upgrade to patched cPanel/WHM versions immediately',
                     'Review cPanel accounts with email-related permissions '
                     'and remove unnecessary privileges',
                     'Enforce multi-factor authentication (MFA) for exposed '
                     'accounts',
                     'Monitor for suspicious files, unexpected changes, or '
                     'unusual root-level processes',
                     'Analyze logs for signs of exploitation attempts'],
 'references': [{'source': 'Security researcher Ali Mustafa (nd abe1526)'}],
 'response': {'communication_strategy': 'Public disclosure and advisory',
              'containment_measures': 'Patches released for affected versions',
              'enhanced_monitoring': 'Monitor for suspicious files, unexpected '
                                     'changes, or unusual root-level '
                                     'processes; analyze logs for exploitation '
                                     'attempts',
              'remediation_measures': 'Upgrade to patched versions '
                                      '(11.110.0.143, 11.134.0.55, '
                                      '11.136.0.39, 11.138.0.4, 11.138.1.9)'},
 'title': 'Critical SQL Injection Flaw in cPanel’s EmailTrack Grants Root '
          'Access (CVE-2026-67401)',
 'type': 'SQL Injection',
 'vulnerability_exploited': 'CVE-2026-67401'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.