cPanel vulnerabilities
CVEs whose affected-version data names the cPanel package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-67401Critical· 9.9PoCA vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
▾ AbyssalWebPros · cPanelEPSS 1.0%via NVD
CVE-2026-65643High· 8.8PoCEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
▾ Midnightcpanel · cpanelEPSS 0.90%via NVD