CVE-2026-67401 turns a cPanel mail account into root through EmailTrack
On September 8, 2026, cPanel disclosed a SQL injection in EmailTrack that lets any mail-account holder write arbitrary files and then execute code as root. Every supported version is affected: on shared hosting, each customer account becomes a doorway to the whole server.