Impact
The vulnerability is a SQL injection in cPanel's EmailTrack component. A mail‑enabled account can inject malicious SQL that is executed with root privileges, enabling an attacker to achieve remote code execution and gain full control over the affected system.
Affected Systems
The flaw exists in cPanel, a web hosting control panel. All currently installed cPanel releases that include the EmailTrack feature are affected; specific version ranges are not listed in the input.
Risk and Exploitability
Scored 9.9 on CVSS, indicating critical severity. No EPSS data is available, but the lack of a KEV listing does not reduce the risk; the remote nature of the attack means any mail-enabled user can attempt exploitation without needing elevated local privileges. If successfully exploited, the attacker receives root access and can modify or destroy data, sabotage services, or pivot to other systems.
OpenCVE Enrichment