The cPanel advisory says almost nothing, and on shared hosting the precondition is a paid plan
2026-09-09Security
CVE-2026-67401 affects every supported version of cPanel and WHM, and lets an authenticated account holder with mail privileges reach root. There is no CVSS score, no explanation of how SQL injection becomes file creation becomes root, no detail on which privilege is required, and no workaround.