New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

Summary: cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

cPanel has patched a serious vulnerability that could allow an authenticated hosting customer to escalate privileges and execute code as root. Tracked as CVE-2026-67401, the flaw affects supported versions of cPanel and WHM and could potentially turn access to a single hosting account into control of an entire server.

The vulnerability is an SQL injection issue involving EmailTrack. According to cPanel, an authenticated user with certain mail-related privileges could exploit the weakness to create arbitrary files and ultimately execute commands with root permissions.

This is particularly dangerous in shared-hosting environments. While customers are normally isolated within their own accounts, root access could allow an attacker to reach other websites, databases and customer information hosted on the same server.

An attacker obtaining this level of access could potentially modify websites, steal credentials, access databases, install malware or establish persistent access. The impact therefore extends well beyond the account initially used to exploit the vulnerability.

cPanel has released fixes across all supported branches. Patched versions include 11.110.0.143, 11.134.0.55, 11.136.0.39 and 11.138.0.4, while WP Squared customers should update to version 11.138.1.9.

Administrators can deploy the update through WHM or force a cPanel update directly from the command line. No official workaround has been provided for servers that cannot immediately install the patched versions.

Some technical details remain undisclosed. cPanel has not explained exactly how the SQL injection progresses to arbitrary file creation and root code execution, likely limiting information that could help attackers develop exploits before administrators have time to patch.

There was no evidence of active exploitation when the vulnerability was disclosed, and CVE-2026-67401 had not been added to CISA’s Known Exploited Vulnerabilities catalog. Public exploit code was also not available at the time of reporting.

However, cPanel remains an attractive target because compromising a hosting control panel can provide access to numerous websites from a single server. Earlier cPanel vulnerabilities have also been exploited in real-world attacks, including ransomware campaigns.

CVE-2026-67401 follows other privilege-escalation vulnerabilities disclosed in cPanel during 2026. Recent flaws have involved database functionality and domain-parking features, with some similarly creating paths toward elevated or root-level access.

Because patching does not remove persistence from a system that may already have been compromised, administrators should also review suspicious authentication activity, unexpected files, newly created accounts and unusual privileged processes.

Hosting providers should prioritize the update even without evidence of widespread exploitation. A vulnerability capable of transforming ordinary customer access into root control represents a serious threat in shared environments, where compromising one account could potentially expose every customer hosted on the same infrastructure.

Key facts

  • cPanel patched a flaw allowing a hosting account to take control of an entire server
  • An authenticated account holder with mail-related privileges could exploit the vulnerability
  • The flaw permitted the creation of arbitrary files on the server via EmailTrack
  • Exploitation could lead to running code as the root user
  • The advisory was published by cPanel on September 8
  • All supported versions of cPanel and WHM were affected

Why it matters

This vulnerability posed a significant threat to server security and data integrity within hosting environments. Successful exploitation could lead to complete server compromise, impacting multiple clients and their hosted services. The prompt patching by cPanel is crucial for maintaining trust and operational stability in the shared hosting ecosystem.