Back to Security Advisories

Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel’s EmailTrack Functionality – September 8, 2026

An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.

High
cPanel

Default Update CMD

sudo /scripts/upcp --force

Situation

An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel’s EmailTrack functionality.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • v11.110.0.143
  • v11.134.0.55
  • v11.136.0.39
  • v11.138.0.4
  • WP2: v11.138.1.9

Impact

Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Acknowledgements

We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Check Your System