Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-67401

Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-67401.

Vendor
cPanel
Product
cPanel & WHM
Affected versions
< 11.110.0.143, < 11.134.0.55, < 11.136.0.39, < 11.138.0.4, < 11.138.1.9
Coverage Span
2026-09-17
Reports
1 related reports

Associated Reports & Timeline

1.
github.com | tool | | original ↗ | #cloud | #rce | #red-team
This repository provides a comprehensive proof-of-concept and local testing lab for CVE-2026-67401, a critical SQL injection vulnerability in cPanel & WHM's EmailTrack functionality. Authenticated users with email-level privileges can inject malicious SQL via the account parameter to execute SELECT ... INTO OUTFILE, dropping a web shell into the document root to achieve remote code execution and escalate privileges to root.
Why it matters: cPanel is widely used in shared web hosting environments. This vulnerability allows low-privileged tenants with mail permissions to achieve full host takeover as root. Administrators should urgently patch cPanel to the latest builds across all supported series.