• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-67401: authenticated sql injection rce in WebPros cPanel

An attacker with a mail-enabled account can exploit a SQL injection flaw in cPanel's EmailTrack component to achieve remote code execution as root (CVE-2026-67401). The issue affects cPanel 11.x releases prior to the fixed builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9. Exploitation requires a mail-enabled account on the target cPanel installation.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.0
9.9CRITICAL
EPSS
0.00861
CWE
CWE-89
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public proof-of-concept exploit code exists, so patch immediately to one of the fixed 11.x builds listed or restrict access to affected services until you can update.

What is CVE-2026-67401?

An attacker with a mail-enabled account can exploit a SQL injection flaw in cPanel's EmailTrack component to achieve remote code execution as root (CVE-2026-67401). The issue affects cPanel 11.x releases prior to the fixed builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9. Exploitation requires a mail-enabled account on the target cPanel installation. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Which versions of WebPros cPanel are affected?

BRANCHAFFECTEDFIXED
11.xbefore 11.134.0.5511.134.0.55
11.xbefore 11.136.0.3911.136.0.39
11.xbefore 11.138.0.411.138.0.4
11.xbefore 11.138.1.911.138.1.9
11.xbefore 11.110.0.14311.110.0.143

Is CVE-2026-67401 being exploited?

Public exploit code is available.

How to fix CVE-2026-67401

  1. Upgrade cPanel 11.x to one of the fixed builds: 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 or 11.138.1.9.
  2. If you cannot patch immediately, restrict or block external access to EmailTrack and mail interfaces and limit mail-enabled accounts.
  3. Force credential resets for mail-enabled accounts and review account permissions.
  4. Monitor cPanel and mail logs for suspicious SQL activity or unexpected root-level actions and follow vendor guidance.

Frequently asked questions

Is CVE-2026-67401 being actively exploited?

Public exploit code is available for CVE-2026-67401.

Which cPanel versions are affected by CVE-2026-67401?

cPanel 11.x releases before the fixed builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9 are affected.

Is there a patch for CVE-2026-67401?

Yes; WebPros published fixes in cPanel 11.x builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9.

Does CVE-2026-67401 require authentication?

Yes; exploitation requires a mail-enabled account on the affected cPanel installation.

References