New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched CVE-2026-67401, a flaw in EmailTrack that could let an authenticated hosting account create files and potentially escalate to root on the entire server. The issue affects all supported cPanel and WHM versions, with fixed builds now available across the 11.110, 11.134, 11.136, 11.138, and WP Squared release lines. #cPanel #WHM #EmailTrack #CVE-2026-67401

Keypoints

  • CVE-2026-67401 affects all supported cPanel and WHM versions.
  • An authenticated account with mail-related privileges can abuse EmailTrack to create files on the server.
  • The flaw may lead to code execution as the root user and full server takeover.
  • cPanel released fixed builds for the 11.110, 11.134, 11.136, 11.138, and WP Squared lines.
  • No public exploit or CISA KEV entry was found at the time of the report.

Read More: https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html