Read-only IOC scanner and mitigation toolkit for cPanel & WHM EmailTrack SQL injection (CVE-2026-67401). Performs version fingerprinting, file integrity checks, log triage, and provides hardening guidance for defenders.
IOC Scanner, Mitigation Tool & Remediation Guide for the cPanel EmailTrack SQL Injection Vulnerability
Keywords: CVE-2026-67401, cPanel exploit, cPanel SQL injection, WHM vulnerability, EmailTrack SQLi, Track Delivery SQL injection, cPanel root RCE, CVSS 9.9, cPanel IOC scanner, cPanel compromise assessment, WHM security advisory, cPanel patch 2026, cPanel 11.136.0.39, cPanel 11.138.0.4, cPanel & WHM security update, web hosting vulnerability, cPanel privilege escalation, mail-enabled cPanel account exploit, cPanel arbitrary file creation, shared hosting takeover, cPanel incident response, cPanel forensics script, cPanel hardening guide, Ali Mustafa rz1027 cPanel, CWE-89 cPanel.
cPanel published the official advisory for this CVE on September 8, 2026, and the CVE Program published the full record — including a CVSS score of 9.9 (Critical) — on September 9, 2026. A patch exists. This is no longer an embargoed/unconfirmed issue — the situation below is quoted directly from cPanel's own advisory:
Situation: An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.
Impact: Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.
As of the last check reflected in this repository (see docs/TIMELINE.md):
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Assigned by HackerOne (the CNA that handles cPanel's bug-bounty-sourced CVEs). CWE-89 (SQL Injection) confirmed as the vulnerability class.This repository intentionally does NOT contain a working SQL injection payload or exploit chain — none has been published anywhere, and this project's purpose is defense, not offense. It provides:
| Field | Detail |
|---|---|
| CVE ID | CVE-2026-67401 |
| CVSS 3.0 Score | 9.9 — Critical |
| CVSS 3.0 Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CWE | CWE-89 (SQL Injection) |
| CVE Assigner (CNA) | HackerOne |
| Bug Bounty Reservation Date | July 29, 2026 |
| Vendor Advisory Published | September 8, 2026, by cPanel/WebPros |
| CVE Record Published | September 9, 2026 |
| Reported by | Ali Mustafa (rz1027) and abed1526 (credited in cPanel's advisory) |
| Component | cPanel & WHM — EmailTrack / "Track Delivery" feature (cPanel > Email > Track Delivery) |
| Vulnerability Class | SQL Injection (CWE-89) → Arbitrary File Creation → Remote Code Execution as root |
| Attack Vector | Network (authenticated) |
| Attack Complexity | Low |
| Privileges Required | Low — a valid cPanel account with mail-related privileges (not a WHM/root account) |
| User Interaction | None |
| Scope | Changed (impact extends beyond the vulnerable component to the whole host) |
| Confidentiality / Integrity / Availability Impact | High / High / High |
| Impact | Full server compromise — code execution as root (per vendor advisory, verbatim) |
| Public Exploitation | None confirmed as of last check |
| Public PoC | None known as of last check |
| CISA KEV Listed? | No, as of last check |
| EPSS Score | N/A (not yet scored), as of last check |
| Affected Products | All supported versions of cPanel & WHM, and WP2 (WP Squared) deployments |
| Official Patched Builds | See table below |
| Release Line | Patched Build |
|---|---|
| 11.110 | 11.110.0.143 |
| 11.134 | 11.134.0.55 |
| 11.136 | 11.136.0.39 |
| 11.138 | 11.138.0.4 |
| WP2 (WP Squared) | 11.138.1.9 |
Note on other release lines: cPanel's July 30, 2026 advisory for the unrelated CVE-2026-58048 also patched the 11.118 and 11.126 lines, but neither line is mentioned in the September 8 advisory for this CVE. That may mean those lines are no longer supported, were already unaffected, or were simply omitted — the vendor advisory does not say. If you're running 11.118 or 11.126, check https://sec.cpanel.net/ directly and strongly consider upgrading to a currently-supported release line regardless.
cve cve-2026-67401 cpanel whm sql-injection sqli rce web-hosting-security ioc incident-response vulnerability-scanner security-advisory blue-team compromise-assessment cpanel-security
CVE-2026-67401 is a SQL injection vulnerability in cPanel & WHM's EmailTrack functionality — the subsystem behind the "Track Delivery" feature that lets a hosting account holder review logs and delivery reports for their own outbound/inbound email. Per cPanel's own advisory, an authenticated cPanel account holder with mail-related privileges (i.e., any ordinary hosting customer with email enabled — not an administrator) can exploit a SQL injection in this feature to create arbitrary files on the server.