A critical SQL execution vulnerability in cPanel, tracked as CVE-2026-58048, allows unauthorized users to execute arbitrary database commands due to improper handling during database renaming. Rated 9.4 on the CVSS scale, it affects shared hosting environments significantly. cPanel has released patches in versions 11.110.0.137, 11.126.0.78, 11.134.0.48, and others to address this flaw. A related, lower-severity bug (CVE-2026-58047) allows limited HTTP request smuggling. No current exploitation has been confirmed.
cPanel fixes high risk SQL bug CVE-2026-58048 in shared hosting
CyberSIXT Evidence Panel
Article by CyberSIXT