Back to Security Advisories

Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel’s EmailTrack Functionality – September 8, 2026

An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.

High
cPanel

Default Update CMD

sudo /scripts/upcp --force

Situation

An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel’s EmailTrack functionality.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • v11.110.0.143
  • v11.134.0.55
  • v11.136.0.39
  • v11.138.0.4
  • WP2: v11.138.1.9

Impact

Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Acknowledgements

We would like to thank Ali Mustafa (rz1027) and abed1526 for responsibly disclosing this vulnerability.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Check Your System