CVE-2026-67401: SQL Injection Vulnerability in cPanel, 9.9 Rating 🔥
A vulnerability in cPanel's EmailTrack component allows an authenticated attacker with mail-related privileges to create arbitrary files on the server via SQL injection. This may lead to code execution as the root user, giving the attacker full control of the server.
Search at Netlas.io:
👉 Link: https://nt.ls/dIEpd
👉 Dork: http.title:cpanel OR http.headers.set_cookie:"cprelogin" OR http.headers.set_cookie:"cpsession"
Vendor's advisory:
https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026
Post #629
384

- 🔥 3
- ❤ 1
- 👾 1