New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
- ID
- 22685
- Status
- summarized
- Published
- 09 Sep 2026, 4:19 PM
- Fetched
- 09 Sep 2026, 5:37 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 09 Sep 2026, 5:38 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
cPanel patched CVE-2026-67401, an SQL injection flaw in the EmailTrack module that lets any authenticated hosting account with mail privileges create arbitrary files and escalate to root access on the entire server. Every supported cPanel/WHM version is affected; fixed builds are 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and WP Squared 11.138.1.9. The advisory does not provide a mitigation for servers that cannot upgrade immediately.
Why it matters
If you or your hosting provider runs cPanel/WHM, patch now via WHM > Home > cPanel > Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root. Any customer account with mail privileges on an unpatched server can seize root and access every other account on that machine — relevant because many Malaysian SMBs and startups still run on cPanel-based shared hosting.
Discussion angle
Ask whether anyone in the group has verified their hosting provider has patched — and whether it's time to move off shared cPanel hosting for production workloads given this is the second root-level cPanel flaw disclosed this year.