CVE Tools
Back to feed
Patch released cPanel rce WHM privilege-escalation

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

cPanel has released a security update to address CVE-2026-67401, a critical vulnerability affecting all supported versions of cPanel and WHM. This flaw, classified as an SQL injection within the EmailTrack functionality, permits an authenticated hosting account with specific mail privileges to create arbitrary files and escalate privileges to execute code as the root user. Because this level of access grants full administrative control over the server, it exposes all customer data and infrastructure to potential compromise. Administrators must immediately update their systems to the designated fixed builds, such as 11.110.0.143 or 11.134.0.55, by running the upgrade script or using the WHM interface.