New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root Swati KhandelwalSep 09, 2026Vulnerability / Web Security cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected. The flaw is tracked as CVE-2026-67401. cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel's developer documentation lists an EmailTrack module…
CVEs: CVE-2026-67401
Original source: thehackernews.com