Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

PoC for CVE-2026-67401: cPanel/WHM EmailTrack SQL Injection Leading to Root RCE

Summary

This repository provides a comprehensive proof-of-concept and local testing lab for CVE-2026-67401, a critical SQL injection vulnerability in cPanel & WHM's EmailTrack functionality. Authenticated users with email-level privileges can inject malicious SQL via the account parameter to execute SELECT ... INTO OUTFILE, dropping a web shell into the document root to achieve remote code execution and escalate privileges to root.

Why it matters

cPanel is widely used in shared web hosting environments. This vulnerability allows low-privileged tenants with mail permissions to achieve full host takeover as root. Administrators should urgently patch cPanel to the latest builds across all supported series.
CVE
CVE-2026-67401
Vendor
cPanel
Product
cPanel & WHM
Affected versions
< 11.110.0.143, < 11.134.0.55, < 11.136.0.39, < 11.138.0.4, < 11.138.1.9
Published
Collected

original ↗