Alertă critică cPanel: CVE-2026-67401 permite acces root

Critical cPanel Alert: CVE-2026-67401 Allows Root Access

A critical SQL injection vulnerability in EmailTrack can allow a cPanel account with email privileges to execute code with root privileges.

cPanel has published a security advisory regarding CVE-2026-67401, a critical SQL injection vulnerability in the EmailTrack functionality of cPanel & WHM.

Vulnerability Impact

An attacker controlling an authenticated cPanel account who has privileges associated with the email service can exploit the vulnerability to create arbitrary files on the server. Successful exploitation can lead to code execution with root privileges, affecting the confidentiality, integrity, and availability of the entire system.

According to public NVD data, the vulnerability has a CVSS score of 9.9 out of 10. The vector indicates a network-based attack, low complexity, low privileges, and no user interaction required.

Recommended Measures

  • Immediately install the security updates provided by cPanel.
  • Verify the status of updates on all managed cPanel & WHM servers.
  • Limit account privileges and review access to features associated with the email service.
  • Monitor for unusual activity, newly created files, and events associated with EmailTrack.
  • Investigate indicators of compromise if a vulnerable system was exposed.

At the time of the NVD data publication, active exploitation was not reported. However, the potential impact is total, and remediation must be treated with the highest priority.

Official source: the cPanel security advisory from September 8, 2026.

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *