CVE-2026-67401

Summary

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

Affected Software

VendorProductVersion RangeStatus
WebProscPanel0 < 11.134.0.55affected
WebProscPanel0 < 11.136.0.39affected
WebProscPanel0 < 11.138.0.4affected
WebProscPanel0 < 11.138.1.9affected
WebProscPanel0 < 11.110.0.143affected

Weaknesses

  • CWE-89: CWE-89 SQL Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References