The cPanel advisory says almost nothing, and on shared hosting the precondition is a paid plan
CVE-2026-67401 affects every supported version of cPanel and WHM, and lets an authenticated account holder with mail privileges reach root. There is no CVSS score, no explanation of how SQL injection becomes file creation becomes root, no detail on which privilege is required, and no workaround.