cPanel Patches Flaw Letting a Single Mail Account Seize Root Control of Your Server
cPanel has released a patch for a serious vulnerability, tracked as CVE-2026-67401, that could allow a single hosting account with mail-related privileges to seize control of an entire server. The issue lies in EmailTrack, a module that tracks email statistics, and is described by cPanel as an SQL injection flaw. Exploiting it reportedly lets an attacker create files of their choosing on the server, ultimately allowing code to run as the root user, the highest level of access on the machine.
This matters because cPanel is widely used web hosting control panel software: a customer normally manages only their own hosting account, while the hosting provider controls the whole server through WHM as root. If an attacker gains root access, they could potentially read every hosting account on that server, alter files and databases, create hidden accounts, install malware, steal credentials, and pivot into customer networks. A similar cPanel flaw was exploited by attackers back in April, underscoring the real-world risk these bugs pose.
Every supported version of cPanel and WHM across the 110, 134, 136 and 138 release lines is affected. cPanel has not clarified whether older 11.118 or 11.126 lines remain supported, nor offered a workaround for servers that cannot update immediately. Administrators can apply the fix via WHM (Home / cPanel / Upgrade to Latest Version) or by running the upcp command as root from the command line.