Hosting providers have a fresh cPanel build to apply after the vendor closed a flaw that handed root-level control to a single account.
The entry point is EmailTrack. A logged-in user with mail privileges can write files anywhere on the machine, then execute code as the root user, per the advisory. cPanel calls the underlying weakness an SQL injection but leaves the specific feature and required privilege unstated. The advisory tracks it as CVE-2026-67401.
Shared hosting amplifies the danger. Tenants only ever see their own slice through cPanel, whereas the hosting provider runs the physical machine as root through WHM. Once that boundary falls, every account’s data becomes readable, files and databases can be altered, silent users added, and malware dropped ahead of a push into customer networks.
Every supported release was affected. Patched builds are 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and WP Squared 11.138.1.9.
April carried a comparable scare, when an authentication bug in the panel was fixed and analysts repeated the same point: panel access is not the same as a single website falling.
Push the update through WHM or the command line now, then look for stray files tied to mail features. On shared infrastructure, one weak tenant puts everyone at risk.
