securityaffairs.com 8/4/2026, 1:13:06 PM · external

Critical cPanel flaw (CVE-2026-58048) lets users run SQL as root

Critical cPanel flaw (CVE-2026-58048) lets users run SQL as root
Developing story vulnerability 3 articles tracked
Critical cPanel SQL execution flaw (CVE-2026-58048) allows root database access
CyberSIXT Evidence Panel
Primary Source support.cpanel.net
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated users to execute SQL commands as root, posing a severe security risk with a CVSS score of 9.4. This flaw affects all supported versions of cPanel and WHM and can lead to operating system-level compromises if exploited. The issue stems from improper handling during the database renaming process, leading to unauthorized privilege escalation. Users are urged to update to patched versions immediately. Temporary measures include revoking MySQL feature access for cPanel users to mitigate risks until updates can be applied.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline