New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers.

cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a valid cPanel account with mail-related privileges to exploit the vulnerability.

While this requirement limits unauthenticated internet-wide exploitation, the potential impact remains severe for shared-hosting providers, managed servers, and organizations with multiple cPanel users.

CVE-2026-67401 is an SQL injection vulnerability in cPanel’s EmailTrack functionality. EmailTrack monitors and reviews email delivery activity, including message routing and delivery information.

A malicious authenticated user can abuse the vulnerable functionality to create arbitrary files on the underlying server. Arbitrary file creation is especially dangerous in a hosting environment because it can let attackers place controlled content in sensitive locations.

Cpanel Vulnerability

cPanel said successful exploitation can result in code execution as the root user. Root access provides unrestricted control over the operating system, allowing attackers to access hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.

An attacker with root-level access could also install persistence mechanisms, deploy malware, alter website content, steal customer data, turn off security tools, or use the compromised server to launch further attacks.

In multi-tenant hosting environments, compromising one privileged cPanel account could put other customers hosted on the same server at risk.

Security researcher Ali Mustafa, also known as (nd abe)1526, reported the vulnerability. The vulnerability affects all supported cPanel/WHM versions before the following patched builds:

cPanel/WHM Release Patched Version
cPanel & WHM 11.110 11.110.0.143
cPanel & WHM 11.134 11.134.0.55
cPanel & WHM 11.136 11.136.0.39
cPanel & WHM 11.138 11.138.0.4
WP2 release 11.138.1.9

Server administrators should verify their installed cPanel/WHM version immediately and upgrade to a patched release. Organizations using managed hosting should also confirm with their provider that the update has been applied across all affected systems.

The primary mitigation is to update cPanel/WHM to the latest available patched version. Administrators should not rely only on restricting public access, because exploitation requires a legitimate authenticated account rather than anonymous access.

Security teams should review cPanel accounts with email-related permissions and remove unnecessary privileges. Enable passwords and multi-factor authentication for accounts that may have been exposed or are no longer required.

Administrators should also investigate for suspicious files, unexpected changes to web directories, modified configuration files, unusual root-level processes, and unexplained outbound network connections. Reviewing cPanel, web-server, authentication, and system logs may help identify exploitation attempts.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server appeared first on Cyber Security News.