A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.

cPanel has patched CVE-2026-67401, a flaw that let a mail-privileged cPanel account reach root on the server it sits on. In the advisory’s own words, an authenticated cPanel account holder with mail-related privileges could “create arbitrary files on the server through cPanel’s EmailTrack functionality,” and successful exploitation “leads to code execution as the root user, giving … Continue reading A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.