CVE-2026-67401 PUBLISHED

Assigner: hackerone
Reserved: 29.07.2026 Published: 09.09.2026 Updated: 10.09.2026

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor WebPros
Product cPanel
Versions Default: unaffected
  • affected from 0 to 11.134.0.55 (excl.)
  • affected from 0 to 11.136.0.39 (excl.)
  • affected from 0 to 11.138.0.4 (excl.)
  • affected from 0 to 11.138.1.9 (excl.)
  • affected from 0 to 11.110.0.143 (excl.)

References

Problem Types

  • CWE-89 SQL Injection CWE