Executive brief
cPanel is a widely-used control panel for managing web hosting accounts and email services. A SQL injection vulnerability in the EmailTrack feature allows mail-enabled account users to execute arbitrary SQL queries and, by extension, run code with root-level privileges on the underlying server. This could lead to complete compromise of the hosting environment, affecting all hosted customers and their data.
Technical details
The vulnerability is a SQL injection flaw in cPanel's EmailTrack component. An attacker with a mail-enabled account can inject malicious SQL through unvalidated input, bypassing query validation. By leveraging the SQL injection to read or modify server-side code or configuration, the attacker can achieve remote code execution (RCE) as the root user. The attack requires only mail account access and does not require network-level privileges; the vulnerability is network-accessible. A patch is expected to be available from cPanel; users should check the official security advisory for mitigation steps and update timelines.
Affected products
- cPanel cPanel <UNKNOWN>
Timeline
- 2026-09-09: disclosed