HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

cPanel Vulnerability Allows Authenticated Mail Account to Execute Root Code

cPanel patched a flaw that lets a hosting account with mail privileges create arbitrary files via EmailTrack and run them as root, affecting all supported versions. The issue highlights the need for continuous monitoring of privileged access and documented patch management for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

cPanel Vulnerability Allows Authenticated Mail Account to Execute Root Code

What Happened — cPanel disclosed a privilege‑escalation flaw that lets a single hosting account with mail‑related privileges create arbitrary files via the EmailTrack feature and then run those files as the root user. The issue affects every supported version of cPanel and WHM and was patched on September 8, 2026.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs must prove that privileged‑account segregation is enforced and that any deviation is detected in near‑real time.
  • The flaw underscores the importance of maintaining up‑to‑date evidence of patch management and vulnerability remediation for audit readiness.

Who Is Affected – Web‑hosting providers, managed cloud platforms, and any organization that runs cPanel/WHM to deliver shared‑hosting services.

Recommended Actions – Apply the September 8 patch immediately; verify the running version across all servers; audit mail‑related accounts for least‑privilege compliance; capture remediation evidence in a control‑mapping repository to support future audits. Source: The Hacker News

Technical Notes – The vulnerability is an authenticated privilege‑escalation path (no CVE disclosed yet) that leverages EmailTrack to write files that are later executed with root privileges. Source: cPanel advisory (Sept 8, 2026)

📰 Original Source
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →