Page 1 of 1

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Posted: Tue Aug 04, 2026 6:54 pm
by Starburst-David
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.


Published Date: Aug 04, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-58048 CVE-2026-58047 CVE-2026-50522

Full Article at:
https://thehackernews.com/2026/08/new-c ... d-let.html