cPanel has patched a serious vulnerability that could allow an authenticated hosting customer to escalate privileges and execute code as root. Tracked as CVE-2026-67401, the flaw affects supported versions of cPanel and WHM and could potentially turn access to a single hosting account into control of an entire server.
The vulnerability is an SQL injection issue involving EmailTrack. According to cPanel, an authenticated user with certain mail-related privileges could exploit the weakness to create arbitrary files and ultimately execute commands with root permissions.
This is particularly dangerous in shared-hosting environments. While customers are normally isolated within their own accounts, root access could allow an attacker to reach other websites, databases and customer information hosted on the same server.
An attacker obtaining this level of access could potentially modify websites, steal credentials, access databases, install malware or establish persistent access. The impact therefore extends well beyond the account initially used to exploit the vulnerability.
cPanel has released fixes across all supported branches. Patched versions include 11.110.0.143, 11.134.0.55, 11.136.0.39 and 11.138.0.4, while WP Squared customers should update to version 11.138.1.9.
Administrators can deploy the update through WHM or force a cPanel update directly from the command line. No official workaround has been provided for servers that cannot immediately install the patched versions.
Some technical details remain undisclosed. cPanel has not explained exactly how the SQL injection progresses to arbitrary file creation and root code execution, likely limiting information that could help attackers develop exploits before administrators have time to patch.
There was no evidence of active exploitation when the vulnerability was disclosed, and CVE-2026-67401 had not been added to CISA’s Known Exploited Vulnerabilities catalog. Public exploit code was also not available at the time of reporting.
However, cPanel remains an attractive target because compromising a hosting control panel can provide access to numerous websites from a single server. Earlier cPanel vulnerabilities have also been exploited in real-world attacks, including ransomware campaigns.
CVE-2026-67401 follows other privilege-escalation vulnerabilities disclosed in cPanel during 2026. Recent flaws have involved database functionality and domain-parking features, with some similarly creating paths toward elevated or root-level access.
Because patching does not remove persistence from a system that may already have been compromised, administrators should also review suspicious authentication activity, unexpected files, newly created accounts and unusual privileged processes.
Hosting providers should prioritize the update even without evidence of widespread exploitation. A vulnerability capable of transforming ordinary customer access into root control represents a serious threat in shared environments, where compromising one account could potentially expose every customer hosted on the same infrastructure.