Junglewise Threat Intelligence

CVE-2026-67401: cPanel SQL injection in EmailTrack component

CVE-2026-67401 · Severity: critical · CVSS 9.9 · Published 2026-09-09

Vendors: cPanel.

Executive brief

cPanel is a widely-used control panel for managing web hosting accounts and email services. A SQL injection vulnerability in the EmailTrack feature allows mail-enabled account users to execute arbitrary SQL queries and, by extension, run code with root-level privileges on the underlying server. This could lead to complete compromise of the hosting environment, affecting all hosted customers and their data.

Technical details

The vulnerability is a SQL injection flaw in cPanel's EmailTrack component. An attacker with a mail-enabled account can inject malicious SQL through unvalidated input, bypassing query validation. By leveraging the SQL injection to read or modify server-side code or configuration, the attacker can achieve remote code execution (RCE) as the root user. The attack requires only mail account access and does not require network-level privileges; the vulnerability is network-accessible. A patch is expected to be available from cPanel; users should check the official security advisory for mitigation steps and update timelines.

Affected products

  • cPanel cPanel <UNKNOWN>

Timeline

  • 2026-09-09: disclosed

References