New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Overview
cPanel has addressed a serious vulnerability that allowed authenticated users to execute SQL commands with root database privileges. This flaw, tracked as CVE-2026-58048 and rated 9.4 on the CVSS scale, breaks the security boundary between individual cPanel accounts and the server's administrative database identity. The issue was fixed in a recent security update, which also addressed two other privilege escalation paths. Hosting customers who use cPanel should be aware of this vulnerability, as it could have allowed unauthorized access to sensitive data or manipulation of critical database functions. It's crucial for users to ensure they are using the latest version of cPanel to mitigate any potential risks associated with this flaw.
Key Takeaways
- Affected Systems: cPanel software, versions affected not specified.
- Action Required: Users should update to the latest version of cPanel to ensure the vulnerability is patched.
- Timeline: Newly disclosed
Original Article Summary
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects
Impact
cPanel software, versions affected not specified.
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users should update to the latest version of cPanel to ensure the vulnerability is patched.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Update, and 2 more.