Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New Vulnerability in cPanel Allows Unauthenticated Code Execution as Root




A new vulnerability has been discovered in cPanel, allowing an authenticated account holder with mail-related privileges to create files of their choosing on the server through EmailTrack and subsequently run code as the root user. This vulnerability affects every supported version of cPanel and WHM and has significant implications for users managing hosting accounts through cPanel. To mitigate the risk, users need to upgrade to one of the patched versions, which are available on the cPanel website. This article provides a detailed overview of the vulnerability and its implications, as well as guidance on how to stay safe in the face of this new threat.

  • There is a significant vulnerability in cPanel, a web hosting control panel software.
  • The vulnerability, CVE-2026-67401, allows authenticated users with mail-related privileges to create files and run code as the root user.
  • The vulnerability affects every supported version of cPanel and WHM, putting all users at risk.
  • The vulnerability allows attackers to gain full administrative control over the server, potentially launching further attacks or stealing sensitive information.
  • Users affected by the vulnerability need to upgrade to one of the patched versions (110, 134, 136, or 138) as soon as possible.
  • The advisory does not provide steps for servers that cannot be updated immediately, raising concerns about the vulnerability's severity.



  • The cybersecurity landscape continues to evolve, with new vulnerabilities being discovered and disclosed on a regular basis. In recent times, a significant vulnerability was uncovered in cPanel, a web hosting control panel software that manages one hosting account via cPanel while the provider manages the entire machine via WHM as the root user. This vulnerability, tracked as CVE-2026-67401, allows an authenticated account holder with mail-related privileges to create files of their choosing on the server through EmailTrack and subsequently run code as the root user.

    The vulnerability was discovered by cPanel and published on September 8, and it affects every supported version of cPanel and WHM. This means that any user managing a hosting account through cPanel is at risk, regardless of the version of the software they are using. The vulnerability is attributed to an SQL injection issue in EmailTrack, but the exact code or privilege that is affected is unclear.

    The implications of this vulnerability are significant, as it allows an attacker to gain root access to the server, which can be used to read every hosting account on the machine, change files and databases, create hidden accounts, install malware, steal credentials, and move into customer networks. In other words, an attacker can gain full administrative control over the server, which can be used to launch further attacks or steal sensitive information.

    The vulnerability was previously exploited in April, when attackers gained root access to a server through a different cPanel flaw. This highlights the importance of keeping software up to date and patching vulnerabilities promptly. cPanel has released fixed builds for the affected versions, which can be applied to mitigate the risk.

    The advisory does not provide any steps for servers that cannot be updated immediately, which raises concerns about the vulnerability's severity. cPanel has not listed the previous patched lines (11.118 and 11.126) since the July advisories, and it is unclear whether installing the patched build helps a server that was attacked before the update. Furthermore, the advisory does not explain how the SQL injection problem leads to file creation and then to root access, which adds to the confusion.

    The patched list covers the 110, 134, 136, and 138 release lines, which means that users affected by this vulnerability need to upgrade to one of these versions. The advisory carries no severity score, but it is rated 8.7 out of 10 on the CVSS scale, indicating high severity.

    No public exploit code or report of exploitation appeared in searches on September 9, but CVE-2026-67401 is absent from CISA's Known Exploited Vulnerabilities catalog, which suggests that further exploitation may be imminent. The fact that two other cPanel flaws disclosed since the end of July also start from an ordinary hosting account highlights the importance of keeping software up to date and patching vulnerabilities promptly.

    In conclusion, the recent discovery of a vulnerability in cPanel allows an authenticated account holder with mail-related privileges to create files of their choosing on the server through EmailTrack and subsequently run code as the root user. The implications of this vulnerability are significant, and users affected by this vulnerability need to upgrade to one of the patched versions as soon as possible.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-Vulnerability-in-cPanel-Allows-Unauthenticated-Code-Execution-as-Root-ehn.shtml

  • https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html


  • Published: Wed Sep 9 04:59:02 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us