सुरक्षा सलाह पर वापस जाएँ

Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel’s EmailTrack Functionality – September 8, 2026

An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.

Critical 9.9 CVSS
cPanel

डिफ़ॉल्ट अपडेट कमांड

sudo /scripts/upcp --force

SharedLicense लाइसेंस के तहत इसका अर्थ

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel’s EmailTrack functionality.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • v11.110.0.143
  • v11.134.0.55
  • v11.136.0.39
  • v11.138.0.4
  • WP2: v11.138.1.9

Impact

Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Acknowledgements

We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-67401?
A CVSS 9.9 SQL injection in cPanel's EmailTrack functionality: an authenticated cPanel account with mail-related privileges can achieve arbitrary file creation and remote code execution as root. Patched in the cPanel security release of 2026-09-08.
Is CVE-2026-67401 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.96% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-67401?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें