CuraSec

Plan active

cPanel EmailTrack flaw allows hosting account to gain root code execution

2026-09-09 15:05 UTC · The Hacker News · read the source ↗ #cpanel#privilege-escalation#web-hosting
  • Engineer — Plan: Every supported cPanel and WHM version is affected; a mail-privileged hosting account can write arbitrary files and escalate to root via EmailTrack. Patch to the latest cPanel/WHM release (advisory published Sep 8) within your next patch window — no PoC or active exploitation is confirmed yet, but root-level impact makes this high priority.
  • SOC/IR — Skip
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.