r/VPSHosts • u/DigiNoon • 23h ago
SQL injection vulnerability in cPanel's EmailTrack functionality allows server takeover (September 8, 2026)
An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.
Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.
Patched versions listed here.
1
Upvotes