A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated users to execute SQL commands as root, posing a severe security risk with a CVSS score of 9.4. This flaw affects all supported versions of cPanel and WHM and can lead to operating system-level compromises if exploited. The issue stems from improper handling during the database renaming process, leading to unauthorized privilege escalation. Users are urged to update to patched versions immediately. Temporary measures include revoking MySQL feature access for cPanel users to mitigate risks until updates can be applied.
Critical cPanel flaw (CVE-2026-58048) lets users run SQL as root
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Critical cPanel flaw (CVE-2026-58048) lets users run SQL as root
securityaffairs.com
-
Critical cPanel flaw lets hosting users run SQL as database root
cybersixt.com
-
cPanel fixes high risk SQL bug CVE-2026-58048 in shared hosting
cybersixt.com