Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel’s EmailTrack Functionality – September 8, 2026
An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.
Default Update CMD
sudo /scripts/upcp --force
Situation
An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel’s EmailTrack functionality.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Acknowledgements
We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo /scripts/upcp --force
References
Check your system for vulnerabilities
Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.
Check Your System