A critical SQL injection vulnerability has been discovered in cPanel & WHM’s EmailTrack functionality. The vulnerability, identified as CVE-2026-67401, could be exploited by an attacker with valid cPanel credentials and mail‑related privileges to gain full control of the affected server.
Affected Systems:
cPanel and WHM: All supported versions prior to v11.110.0.143, v11.134.0.55, v11.136.0.39, v11.138.0.4
WP Squared (WP2): All supported versions prior to v11.138.1.9
Security Risks
Successful exploitation could allow an attacker with an authenticated cPanel account and mail‑related privileges to execute code with root‑level access, which may lead to complete server compromise and exposure of all hosted accounts, websites, and databases.