CVE-2026-67401 is an authenticated SQL injection vulnerability in the EmailTrack functionality of cPanel & WHM. A hosting-account user with unspecified mail-related privileges can exploit the flaw to create arbitrary files on the underlying server. cPanel states that this capability can ultimately be leveraged to execute code with root privileges. All supported cPanel & WHM versions were affected prior to the vendor-fixed builds.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cPanel EmailTrack SQL-injection issue that may allow an authenticated hosting account with email-related privileges to create arbitrary server files and ultimately execute code with root privileges, enabling compromise of the entire hosting server.
A critical authenticated SQL-injection flaw in cPanel/WHM EmailTrack. An attacker with a valid cPanel account holding mail-related privileges can create arbitrary files and potentially obtain root-level code execution on the vulnerable server, creating a serious multi-tenant hosting risk.
A critical authenticated SQL injection vulnerability in cPanel/WHM EmailTrack. An attacker with a valid cPanel account and mail-related privileges can create arbitrary files and potentially achieve code execution as root, enabling full server compromise.
An authenticated SQL injection vulnerability in cPanel/WHM's EmailTrack functionality that can reportedly enable arbitrary file creation and subsequent code execution as root, allowing a single hosting account to compromise the entire server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.