Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-67401-cPanel-EmailTrack-SQLi — Read-only IOC scanner and mitigation toolkit for cPanel & WHM EmailTrack SQL injection (CVE-2026-67401). Performs version fingerprinting, file integrity checks, log triage, and provides hardening guidance for defenders. | Kitploit
工具/GitHubGitHub/jithinkrishnanrs/cve-2026-67401-cpanel-emailtrack-sqli
Cloud Infrastructure SecurityDefensive ToolsVulnerability ScannersConfiguration AuditingWeb SecurityDigital ForensicsLearning & EducationIncident ResponseDatabase Security

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubjithinkrishnanrs/cve-2026-67401-cpanel-emailtrack-sqli

CVE-2026-67401-cPanel-EmailTrack-SQLi

Read-only IOC scanner and mitigation toolkit for cPanel & WHM EmailTrack SQL injection (CVE-2026-67401). Performs version fingerprinting, file integrity checks, log triage, and provides hardening guidance for defenders.

查看仓库
3017天前尚未审核
内容在请求的语言中不可用。显示英文版本。

CVE-2026-67401 — cPanel & WHM EmailTrack SQL Injection → Root RCE

IOC Scanner, Mitigation Tool & Remediation Guide for the cPanel EmailTrack SQL Injection Vulnerability

CVE CVSS Vector Product Advisory KEV Status License

Keywords: CVE-2026-67401, cPanel exploit, cPanel SQL injection, WHM vulnerability, EmailTrack SQLi, Track Delivery SQL injection, cPanel root RCE, CVSS 9.9, cPanel IOC scanner, cPanel compromise assessment, WHM security advisory, cPanel patch 2026, cPanel 11.136.0.39, cPanel 11.138.0.4, cPanel & WHM security update, web hosting vulnerability, cPanel privilege escalation, mail-enabled cPanel account exploit, cPanel arbitrary file creation, shared hosting takeover, cPanel incident response, cPanel forensics script, cPanel hardening guide, Ali Mustafa rz1027 cPanel, CWE-89 cPanel.


✅ Official Vendor Status (Confirmed)

cPanel published the official advisory for this CVE on September 8, 2026, and the CVE Program published the full record — including a CVSS score of 9.9 (Critical) — on September 9, 2026. A patch exists. This is no longer an embargoed/unconfirmed issue — the situation below is quoted directly from cPanel's own advisory:

Situation: An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.

Impact: Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.

— cPanel Security Advisory, September 8, 2026

As of the last check reflected in this repository (see docs/TIMELINE.md):

  • CVSS 3.0 Base Score: 9.9 (Critical) — Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Assigned by HackerOne (the CNA that handles cPanel's bug-bounty-sourced CVEs). CWE-89 (SQL Injection) confirmed as the vulnerability class.
  • Bug bounty reservation date: July 29, 2026 — meaning the bug was privately reported roughly six weeks before the public advisory, consistent with cPanel's typical embargo-until-patch practice.
  • No public proof-of-concept or exploit code has been found (checked general web search, GitHub PoC-index projects, and exploit-tracking aggregators).
  • No confirmed in-the-wild exploitation, and the CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of the last check. EPSS exploitation-probability scoring was also unavailable (N/A) as of the last check.
  • cPanel's advisory does not explain the technical mechanism connecting the SQL injection to arbitrary file creation to root execution, and does not offer an interim mitigation step for servers that can't patch immediately (unlike its July 30, 2026 advisory for the similar CVE-2026-58048, where it explicitly told administrators to temporarily disable a feature).

This repository intentionally does NOT contain a working SQL injection payload or exploit chain — none has been published anywhere, and this project's purpose is defense, not offense. It provides:

  • Version/patch-level fingerprinting against the real, official patched builds (below)
  • Indicator-of-Compromise (IOC) scanning based on the disclosed impact of the bug
  • Log and file-integrity triage
  • An unofficial stopgap mitigation script, modeled on cPanel's own precedent for a structurally similar bug, for hosts that can't patch same-day

1. Vulnerability Summary

FieldDetail
CVE IDCVE-2026-67401
CVSS 3.0 Score9.9 — Critical
CVSS 3.0 VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWECWE-89 (SQL Injection)
CVE Assigner (CNA)HackerOne
Bug Bounty Reservation DateJuly 29, 2026
Vendor Advisory PublishedSeptember 8, 2026, by cPanel/WebPros
CVE Record PublishedSeptember 9, 2026
Reported byAli Mustafa (rz1027) and abed1526 (credited in cPanel's advisory)
ComponentcPanel & WHM — EmailTrack / "Track Delivery" feature (cPanel > Email > Track Delivery)
Vulnerability ClassSQL Injection (CWE-89) → Arbitrary File Creation → Remote Code Execution as root
Attack VectorNetwork (authenticated)
Attack ComplexityLow
Privileges RequiredLow — a valid cPanel account with mail-related privileges (not a WHM/root account)
User InteractionNone
ScopeChanged (impact extends beyond the vulnerable component to the whole host)
Confidentiality / Integrity / Availability ImpactHigh / High / High
ImpactFull server compromise — code execution as root (per vendor advisory, verbatim)
Public ExploitationNone confirmed as of last check
Public PoCNone known as of last check
CISA KEV Listed?No, as of last check
EPSS ScoreN/A (not yet scored), as of last check
Affected ProductsAll supported versions of cPanel & WHM, and WP2 (WP Squared) deployments
Official Patched BuildsSee table below

Official Patched Builds (from cPanel's advisory)

Release LinePatched Build
11.11011.110.0.143
11.13411.134.0.55
11.13611.136.0.39
11.13811.138.0.4
WP2 (WP Squared)11.138.1.9

Note on other release lines: cPanel's July 30, 2026 advisory for the unrelated CVE-2026-58048 also patched the 11.118 and 11.126 lines, but neither line is mentioned in the September 8 advisory for this CVE. That may mean those lines are no longer supported, were already unaffected, or were simply omitted — the vendor advisory does not say. If you're running 11.118 or 11.126, check https://sec.cpanel.net/ directly and strongly consider upgrading to a currently-supported release line regardless.

Suggested GitHub Topics for This Repository

cve cve-2026-67401 cpanel whm sql-injection sqli rce web-hosting-security ioc incident-response vulnerability-scanner security-advisory blue-team compromise-assessment cpanel-security

Plain-English Description

CVE-2026-67401 is a SQL injection vulnerability in cPanel & WHM's EmailTrack functionality — the subsystem behind the "Track Delivery" feature that lets a hosting account holder review logs and delivery reports for their own outbound/inbound email. Per cPanel's own advisory, an authenticated cPanel account holder with mail-related privileges (i.e., any ordinary hosting customer with email enabled — not an administrator) can exploit a SQL injection in this feature to create arbitrary files on the server.

下载工具