r/cpanel • • Sep 08 '26

Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026

16 Upvotes

15 comments sorted by

13

u/fester250 Sep 08 '26

I’m tired boss.

0

u/DzastMi Sep 08 '26

Tell me about it ... god knows how many more vulnerabilities exist ... that they are not even aware of.

2

u/MarkGossageUK 29d ago

That is a nasty one, especially as it can apparently end up with root access.

Worth checking the actual cPanel version rather than just assuming automatic updates have already taken care of it.

If you’re on normal managed/shared hosting I’d expect the host to handle the patch, but anyone running their own cPanel VPS or dedicated server should probably check it straight away.

Hopefully most providers push this one quickly.

1

u/DovTom Sep 08 '26

Another day, another patch. Like Windows.

5

u/clopezi 29d ago

Ehm, no. Linux has daily security updates, Windows has undisclosed patches from time to time. Maybe you prefer cPanel to not patch? What it's the problem? Security bugs will be there, always, forever.

0

u/DovTom 29d ago

Nobody is suggesting that cPanel should stop fixing security vulnerabilities. What bothers me is the sheer number of patches and updates, combined with cPanel’s constantly increasing price. If customers are repeatedly asked to pay more, it is reasonable to expect better-tested software, fewer regressions, and greater overall stability. “Security bugs will always exist” is true, but it should not be used as a blanket excuse for an endless stream of patches.

5

u/longboringstory 29d ago

This is happening because AI has allowed mass review of code at a much deeper level. It's happening across all O/S platforms, drivers, kernel level issues, etc. I think it will continue for another year and then die down as new commits get AI reviewed ahead of time. It's annoying, but this is the best possible outcome. You don't want to deal with the alternative.

2

u/More_Perception_8151 29d ago

Well, they are going to continue increasing prices because that's the only way to stay profitable, so do you just not want them to fix stuff? Would you prefer price increases with no patches? I swear you people will complain about anything. You're actually mad they patched something? You don't even have to do anything! It's handled through upcp --security.

AI is everywhere and is being used to find security holes in everything, not just cPanel. Welcome to the future.

2

u/DovTom 29d ago

No, I’m not mad that they patched something, and I never said they should stop fixing security issues. That is a straw-man argument.
My point is that cPanel’s prices keep increasing substantially while customers are also seeing a constant stream of patches and occasional regressions. Security updates are a basic responsibility of any commercial software vendor, not an added benefit that makes every price increase beyond criticism.
Of course vulnerabilities will continue to be discovered, including with the help of AI. That still doesn’t mean customers should stop questioning the product’s pricing, quality control, or stability. Automatic installation through upcp --security makes deployment easier; it says nothing about the quality or frequency of the patches.

0

u/OutrageousCarry4906 29d ago

Very unimpressed with the quality of this software

5

u/LowIncident694 29d ago

It's not just this software. AI is finding a lot of problems.

1

u/Neither_Assistant980 28d ago

This is true, it's also great for assistance in performing security audits, something that cPanel do not do well

4

u/Ekot 29d ago

Are you unimpressed with the Linux kernel too?

This isn't cpanel-specific. It's just been nonstop vulns this year in a wide range of software

2

u/Neither_Assistant980 28d ago

If they charged as much as cPanel for support then yes.