On September 8, 2026, cPanel published a security advisory for CVE-2026-67401, a SQL vulnerability in cPanel/WHM’s EmailTrack functionality. The documented scenario involves an already authenticated cPanel account holder with mail-related privileges: that account could create arbitrary files on the server. Successful exploitation could then allow root code execution and full server control.
cPanel asks administrators to install the fixed version for the branch they run. The public sources reviewed describe the vulnerability and its fixes, but do not publish a victim list or evidence that a particular server was compromised. Treat the exposure as a maintenance priority while keeping the documented impact separate from indicators that must be checked locally.
What cPanel confirmed
cPanel places all supported versions in the affected scope until a fix is installed. The fixed versions are 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and, for WP2, 11.138.1.9. The vendor credits Ali Mustafa and abed1526 for responsible disclosure.
For a hosting provider or team administering websites, the key detail is the combination of application scope and privilege level: the advisory does not describe anonymous access to EmailTrack, but an authenticated cPanel account with mail-related privileges. That does not make patching optional: a compromised, reused, or over-privileged account can become the starting point for server compromise.
What CVE-2026-67401 enables
cPanel describes arbitrary file creation through EmailTrack, while Check Point summarizes the flaw as SQL injection that allows a remote attacker to reach root code execution through the EmailTrack component. The descriptions align on impact: the exploitation path starts at a cPanel function available to an authenticated account and can reach the host system with root privileges.
That possibility does not prove that every vulnerable server was hit or that specific data was stolen. A sound review should separate three questions: was the installed version in scope, did accounts have the required privileges, and do logs or files show unusual activity during the exposure window?
Who needs to act
cPanel/WHM administrators should identify the installed branch and verify the exact server version, then apply the matching fix. The correct version depends on the branch; do not mechanically substitute one number for another without considering compatibility and cPanel’s update procedure.
The inventory should include cPanel accounts with mail functions, WHM access, deployment accounts, and integrations that can create or modify files on the host. The vulnerability concerns EmailTrack, but the review should also cover administration paths sharing the same server and secrets.
Checks after exposure
After updating, record the change time and observed version. Review cPanel/WHM logs, authentication and mail logs, and files recently created or modified in directories managed by affected accounts. An unexpected file, unusual login, or newly added scheduled task is a signal to correlate, not isolated proof.
If an intrusion indicator appears, isolate the server according to your incident-response procedure, preserve evidence, and review related accounts and keys. Revoke and replace administration, mail, deployment, and database-access secrets when exposure is possible. The cPanel update remains necessary even if the investigation ultimately finds no compromise.
Reduce risk around privileged accounts
The fix protects the cPanel/WHM version; it does not repair a reused password, an over-privileged account, or a key that has never been rotated. Give cPanel and WHM accounts only the access they need, remove stale permissions, and plan coordinated rotation when an investigation requires several related credentials to be revoked.
For teams managing several hosting environments, document who owns each access, when it was last rotated, and which service it reaches. That visibility helps prevent an old panel, mail, or deployment password from remaining active after a security update.
How Soclyde fits
Soclyde does not patch cPanel/WHM, inspect server logs, or replace incident response. Its role is narrower: generate a unique secret for each administrative account, keep it in a local-first encrypted vault, and make rotation easier when access must be revoked or replaced.
This separation reduces reuse of the same password across a hosting panel, email, and a deployment tool. It does not make a vulnerable server safe or prove that an account was compromised; cPanel patching, local investigation, and revocation remain the priorities.
Key takeaways
CVE-2026-67401 affects cPanel/WHM EmailTrack and can lead to root execution after successful exploitation. Check your branch, install the fixed version, record evidence of the update, and review logs and created files if the server was exposed.
If the investigation indicates risk to associated accounts, revoke and replace the affected secrets. To reduce password reuse across services, read the secure password generator guide or contact Soclyde.



