Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

post, augustus 4, 2026augustus 17, 2026

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
vulnerability 2026

Bericht navigatie

Previous post
Next post

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes