AI Weekly Malaysia

Back to items Summaries

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

ID
22685
Status
summarized
Published
09 Sep 2026, 4:19 PM
Fetched
09 Sep 2026, 5:37 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
09 Sep 2026, 5:38 PM
Tags
Audience
developerssaas_startup_founders

What happened

cPanel patched CVE-2026-67401, an SQL injection flaw in the EmailTrack module that lets any authenticated hosting account with mail privileges create arbitrary files and escalate to root access on the entire server. Every supported cPanel/WHM version is affected; fixed builds are 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and WP Squared 11.138.1.9. The advisory does not provide a mitigation for servers that cannot upgrade immediately.

Why it matters

If you or your hosting provider runs cPanel/WHM, patch now via WHM > Home > cPanel > Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root. Any customer account with mail privileges on an unpatched server can seize root and access every other account on that machine — relevant because many Malaysian SMBs and startups still run on cPanel-based shared hosting.

Discussion angle

Ask whether anyone in the group has verified their hosting provider has patched — and whether it's time to move off shared cPanel hosting for production workloads given this is the second root-level cPanel flaw disclosed this year.

Top