cPanel Vulnerability Allows Authenticated Mail Account to Execute Root Code
What Happened — cPanel disclosed a privilege‑escalation flaw that lets a single hosting account with mail‑related privileges create arbitrary files via the EmailTrack feature and then run those files as the root user. The issue affects every supported version of cPanel and WHM and was patched on September 8, 2026.
Why It Matters for Trust & Control Assurance
- Continuous control‑assurance programs must prove that privileged‑account segregation is enforced and that any deviation is detected in near‑real time.
- The flaw underscores the importance of maintaining up‑to‑date evidence of patch management and vulnerability remediation for audit readiness.
Who Is Affected – Web‑hosting providers, managed cloud platforms, and any organization that runs cPanel/WHM to deliver shared‑hosting services.
Recommended Actions – Apply the September 8 patch immediately; verify the running version across all servers; audit mail‑related accounts for least‑privilege compliance; capture remediation evidence in a control‑mapping repository to support future audits. Source: The Hacker News
Technical Notes – The vulnerability is an authenticated privilege‑escalation path (no CVE disclosed yet) that leverages EmailTrack to write files that are later executed with root privileges. Source: cPanel advisory (Sept 8, 2026)