SOCLYDE logo
Current languageEN
Cybersecurity newscPanelWHMCVE

Cve-2026-67401: cpanel/whm fixes a critical emailtrack flaw

A SQL injection flaw in cPanel/WHM let an authenticated account create files and, after successful exploitation, execute code as root. Here are the fixed versions and priority actions.

By Soclyde Team

Administrator checking a maintenance panel in a web-hosting server room

In summary

  • CVE-2026-67401 affects cPanel/WHM EmailTrack: an authenticated cPanel account with mail-related privileges could create arbitrary files on the server.
  • Successful exploitation could lead to root code execution and full server control; the sources reviewed do not confirm a list of victims.
  • Update cPanel/WHM to the fixed version for your branch: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or WP2 11.138.1.9.

Explore next

Soclyde resources

Article contents

On September 8, 2026, cPanel published a security advisory for CVE-2026-67401, a SQL vulnerability in cPanel/WHM’s EmailTrack functionality. The documented scenario involves an already authenticated cPanel account holder with mail-related privileges: that account could create arbitrary files on the server. Successful exploitation could then allow root code execution and full server control.

cPanel asks administrators to install the fixed version for the branch they run. The public sources reviewed describe the vulnerability and its fixes, but do not publish a victim list or evidence that a particular server was compromised. Treat the exposure as a maintenance priority while keeping the documented impact separate from indicators that must be checked locally.

What cPanel confirmed

cPanel places all supported versions in the affected scope until a fix is installed. The fixed versions are 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and, for WP2, 11.138.1.9. The vendor credits Ali Mustafa and abed1526 for responsible disclosure.

For a hosting provider or team administering websites, the key detail is the combination of application scope and privilege level: the advisory does not describe anonymous access to EmailTrack, but an authenticated cPanel account with mail-related privileges. That does not make patching optional: a compromised, reused, or over-privileged account can become the starting point for server compromise.

What CVE-2026-67401 enables

cPanel describes arbitrary file creation through EmailTrack, while Check Point summarizes the flaw as SQL injection that allows a remote attacker to reach root code execution through the EmailTrack component. The descriptions align on impact: the exploitation path starts at a cPanel function available to an authenticated account and can reach the host system with root privileges.

That possibility does not prove that every vulnerable server was hit or that specific data was stolen. A sound review should separate three questions: was the installed version in scope, did accounts have the required privileges, and do logs or files show unusual activity during the exposure window?

Who needs to act

cPanel/WHM administrators should identify the installed branch and verify the exact server version, then apply the matching fix. The correct version depends on the branch; do not mechanically substitute one number for another without considering compatibility and cPanel’s update procedure.

The inventory should include cPanel accounts with mail functions, WHM access, deployment accounts, and integrations that can create or modify files on the host. The vulnerability concerns EmailTrack, but the review should also cover administration paths sharing the same server and secrets.

Checks after exposure

After updating, record the change time and observed version. Review cPanel/WHM logs, authentication and mail logs, and files recently created or modified in directories managed by affected accounts. An unexpected file, unusual login, or newly added scheduled task is a signal to correlate, not isolated proof.

If an intrusion indicator appears, isolate the server according to your incident-response procedure, preserve evidence, and review related accounts and keys. Revoke and replace administration, mail, deployment, and database-access secrets when exposure is possible. The cPanel update remains necessary even if the investigation ultimately finds no compromise.

Reduce risk around privileged accounts

The fix protects the cPanel/WHM version; it does not repair a reused password, an over-privileged account, or a key that has never been rotated. Give cPanel and WHM accounts only the access they need, remove stale permissions, and plan coordinated rotation when an investigation requires several related credentials to be revoked.

For teams managing several hosting environments, document who owns each access, when it was last rotated, and which service it reaches. That visibility helps prevent an old panel, mail, or deployment password from remaining active after a security update.

How Soclyde fits

Soclyde does not patch cPanel/WHM, inspect server logs, or replace incident response. Its role is narrower: generate a unique secret for each administrative account, keep it in a local-first encrypted vault, and make rotation easier when access must be revoked or replaced.

This separation reduces reuse of the same password across a hosting panel, email, and a deployment tool. It does not make a vulnerable server safe or prove that an account was compromised; cPanel patching, local investigation, and revocation remain the priorities.

Key takeaways

CVE-2026-67401 affects cPanel/WHM EmailTrack and can lead to root execution after successful exploitation. Check your branch, install the fixed version, record evidence of the update, and review logs and created files if the server was exposed.

If the investigation indicates risk to associated accounts, revoke and replace the affected secrets. To reduce password reuse across services, read the secure password generator guide or contact Soclyde.

Frequently asked questions

Who is affected by CVE-2026-67401?

All supported cPanel/WHM servers are affected until the fixed version for their branch is installed. The documented scenario requires an authenticated cPanel account with mail-related privileges and uses the EmailTrack functionality.

Which cPanel/WHM version should be installed?

Install the fixed version for your branch: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or WP2 11.138.1.9. Verify the actual installed version after updating and follow cPanel’s update instructions.

Should passwords be changed after updating?

The update fixes the software but, by itself, does not prove that a secret was exposed. If your server was vulnerable, review logs and created files, then rotate administration, mail, and deployment credentials whenever exposure is possible or an intrusion indicator is found.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading