CVE-2026-67401: SQL Injection
Published Sep 9, 2026
·Updated
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Event History
Sep 9, 2026
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker needs a mail-enabled account. The attack can be performed remotely and does not require user interaction.
2
What level of access could an attacker gain?
Successful exploitation can result in remote code execution as root, with high impact to confidentiality, integrity, and availability.
3
Is this exploitable without authentication?
No. The vector indicates low privileges are required, and the description specifically identifies a mail-enabled account as the prerequisite.