DIRAS TAKE
Urgent: public proof-of-concept exploit code exists, so patch immediately to one of the fixed 11.x builds listed or restrict access to affected services until you can update.
What is CVE-2026-67401?
An attacker with a mail-enabled account can exploit a SQL injection flaw in cPanel's EmailTrack component to achieve remote code execution as root (CVE-2026-67401). The issue affects cPanel 11.x releases prior to the fixed builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9. Exploitation requires a mail-enabled account on the target cPanel installation. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Which versions of WebPros cPanel are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | before 11.134.0.55 | 11.134.0.55 |
| 11.x | before 11.136.0.39 | 11.136.0.39 |
| 11.x | before 11.138.0.4 | 11.138.0.4 |
| 11.x | before 11.138.1.9 | 11.138.1.9 |
| 11.x | before 11.110.0.143 | 11.110.0.143 |
Is CVE-2026-67401 being exploited?
Public exploit code is available.
How to fix CVE-2026-67401
- Upgrade cPanel 11.x to one of the fixed builds: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 or 11.138.1.9.
- If you cannot patch immediately, restrict or block external access to EmailTrack and mail interfaces and limit mail-enabled accounts.
- Force credential resets for mail-enabled accounts and review account permissions.
- Monitor cPanel and mail logs for suspicious SQL activity or unexpected root-level actions and follow vendor guidance.
Frequently asked questions
Is CVE-2026-67401 being actively exploited?
Public exploit code is available for CVE-2026-67401.
Which cPanel versions are affected by CVE-2026-67401?
cPanel 11.x releases before the fixed builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9 are affected.
Is there a patch for CVE-2026-67401?
Yes; WebPros published fixes in cPanel 11.x builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9.
Does CVE-2026-67401 require authentication?
Yes; exploitation requires a mail-enabled account on the affected cPanel installation.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67401
- cve.org/CVERecord?id=CVE-2026-67401
- support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026
- All WebPros CVEs on CVE Radar
- CVEs published in September 2026