HackerFeeds

CyberSecurity News

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker News
· September 9, 2026

AI summary

A vulnerability in cPanel has been discovered that allows a hosting account with mail privileges to gain control of the entire server. This is made possible by an authenticated account holder creating files on the server via EmailTrack, which can then be used to run code with root user privileges. The issue affects all supported versions of cPanel and WHM. cPanel published an advisory on this flaw, indicating that it has been patched. The patch addresses a significant security risk, as a single hosting account can potentially take control of the server.

Read the full article at The Hacker Newsthehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.