← All articles

New cPanel flaw lets a mail-privileged hosting account run code as root

cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.

Check
Update cPanel and WHM to the patched builds now, review which accounts hold mail-related privileges, and because no indicators were published, hunt broadly for unexpected root processes, files, and hidden accounts.
Affected
Shared-hosting providers and multi-tenant servers running unpatched cPanel and WHM (CVE-2026-67401); an authenticated account with mail privileges can inject SQL, create files, and execute code as root, taking over the entire machine.
Fix
Patch to the fixed builds, restrict mail-related privileges, isolate tenants, monitor for root-level file creation and command execution, rotate credentials on any suspected compromised server, and assume shared servers are one-account-from-root.