Close Menu
NCIJ Network NCIJ Network
    What's Hot

    AfD ‘remigration’ plans amount to ‘ethnic cleansing,’ says Merz – POLITICO

    September 9, 2026

    Anthropic researcher believes more than 10% chance AI ‘could kill all humans’

    September 9, 2026

    CloudNC aims to accelerate AI supply chain machining

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AfD ‘remigration’ plans amount to ‘ethnic cleansing,’ says Merz – POLITICO
    • Anthropic researcher believes more than 10% chance AI ‘could kill all humans’
    • CloudNC aims to accelerate AI supply chain machining
    • New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
    • Mexico Seizes 300 Crypto Mining Rigs Wired Into a Hydroelectric Dam
    • Vantara works with lobbyist tied to Trump Jr. and pro-hunting groups
    • ABS certifies FPSO design for South American and West African deep waters
    • Ectopic Pregnancy Deaths Have Nearly Doubled. It’s Worse in Abortion-Ban States. — ProPublica
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 09, 2026Vulnerability / Web Security

    cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.

    cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

    The flaw is tracked as CVE-2026-67401. cPanel’s advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs. cPanel’s developer documentation lists an EmailTrack module that tracks email statistics, and the advisory does not say whether that is the affected code.

    cPanel is web hosting control panel software. A customer manages one hosting account via cPanel, while the provider manages the entire machine via WHM as the root user.

    Attackers exploited a different cPanel flaw in April. Taking over the panel is not the same as breaking into one customer’s website, the security company Hadrian said at the time, because WHM gives an attacker root administrative access to the server.

    Cybersecurity

    An attacker with that access can read every hosting account on the machine, change files and databases, create hidden accounts, install malware, steal credentials, and move into customer networks.

    cPanel named these fixed builds:

    Release line Fixed build
    11.110 11.110.0.143
    11.134 11.134.0.55
    11.136 11.136.0.39
    11.138 11.138.0.4
    WP Squared 11.138.1.9

    A server can be updated from WHM under Home / cPanel / Upgrade to Latest Version. On the command line, cPanel’s instructions are to log in as root and run /usr/local/cpanel/scripts/upcp –force.

    The advisory does not explain how an SQL injection problem leads to file creation and then to root access.

    The advisory also offers nothing to do in the meantime for servers that cannot update straight away. cPanel gave a step like that in its July 30 advisory for a database flaw, where administrators who could not upgrade were told they could temporarily remove the MySQL feature from cPanel users.

    The patched list covers the 110, 134, 136 and 138 release lines. cPanel patched the 11.118 and 11.126 lines in its July advisories, has not listed them since, and has not said whether they are still supported.

    For the August flaw, the CVE record lists every version from 11.112.0.0 up to, but not including, 11.134.0.53 in the affected range and lists no fixed build in lines 118 or 126.

    cPanel also does not say whether installing the patched build helps a server that was attacked before the update, or how an administrator would check.

    The advisory carries no severity score. cPanel’s recent CVEs are assigned through HackerOne, and the scores have been arriving in the CVE record rather than in the advisory.

    Cybersecurity

    The record for the August flaw was published on September 1, five days after that advisory. It scores that flaw 8.7 out of 10 on the CVSS scale, indicating high severity. No record had been published for CVE-2026-67401 when The Hacker News checked the CVE Program’s record store on September 9.

    No public exploit code or report of exploitation appeared in searches on September 9, and CVE-2026-67401 is absent from CISA’s Known Exploited Vulnerabilities catalog in the version released on September 8.

    Neither check rules out exploitation. That April flaw, an authentication bypass that needed no account at all, is in the same catalog with known use in ransomware campaigns.

    Two other cPanel flaws disclosed since the end of July also start from an ordinary hosting account. A July 30 advisory covered a database flaw that could let an account with access to the database feature run database commands with full administrative privileges. cPanel described an August 27 flaw in domain parking that ended the same way as this one: code execution as root.

    Repositories that present themselves as working exploits for those two flaws were online when The Hacker News checked on September 9.

    cPanel credits Ali Mustafa (rz1027) and abed1526 with reporting this one. The CVE record for the August flaw credits the same name, Ali Mustafa.

    Neither cPanel’s advisories nor that record ties the two flaws to the same code. The records classify them differently: eval injection for the August flaw and SQL injection for this one, according to cPanel’s own title.

    account Code cPanel Flaw hosting lets Mail privileges Root Run
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

    N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Meta continues to run ads promoting child sexual abuse material in India: report

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    AfD ‘remigration’ plans amount to ‘ethnic cleansing,’ says Merz – POLITICO

    September 9, 2026

    Anthropic researcher believes more than 10% chance AI ‘could kill all humans’

    September 9, 2026

    CloudNC aims to accelerate AI supply chain machining

    September 9, 2026

    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    September 9, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    AfD ‘remigration’ plans amount to ‘ethnic cleansing,’ says Merz – POLITICO

    September 9, 2026

    Anthropic researcher believes more than 10% chance AI ‘could kill all humans’

    September 9, 2026

    CloudNC aims to accelerate AI supply chain machining

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.