New cPanel Flaw Grants Root Access, Threatens Millions of Websites

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
A fresh vulnerability in cPanel EmailTrack functionality, tracked as CVE-2026-67401, is sending shivers down the spines of web hosting providers worldwide. This critical SQL injection flaw allows any authenticated cPanel account holder with mail-related privileges to create arbitrary files on a server, ultimately escalating to full root access. This means an attacker could seize complete control over an entire server, compromising every website, database, and email account hosted on it. This isn't just another bug; it's a 'keys to the kingdom' scenario for attackers, threatening the millions of websites that rely on cPanel ubiquitous web hosting control panel software. With root privileges, malicious actors can steal sensitive data, deploy ransomware, install persistence mechanisms, or pivot into customer networks. The discovery comes amidst a concerning pattern, marking at least three major cPanel root-level vulnerabilities disclosed this year alone, including the widely exploited CVE-2026-41940 authentication bypass in April and CVE-2026-65643 in August, which also allowed root access through domain parking features. cPanel has already released urgent patches, and administrators are being strongly advised to update their systems immediately by running '/usr/local/cpanel/scripts/upcp --force' or using the WHM interface. While there are currently no public exploits or reports of active exploitation for CVE-2026-67401, and it's not yet listed in CISA's Known Exploited Vulnerabilities Catalog, the severity demands swift action to prevent potential widespread compromise. Hosting providers and individual server owners must prioritize these updates to secure their infrastructure against this severe threat.