CVE Tools

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

The Hacker NewsBy The Hacker News

PatchcPanel & WHMWP Squared

Our summary

cPanel has addressed a critical vulnerability allowing authenticated users to execute SQL commands in the database root context, potentially leading to full system compromise. Tracked as CVE-2026-58048 (CVSS score 9.4), it impacts all supported versions of cPanel & WHM and WP Squared. Attackers need valid account access and MySQL/MariaDB privileges to exploit this flaw. The fix was included in several updated builds, including 11.110.0.137 and 138.1.6 for WP Squared. Administrators unable to update immediately should temporarily disable MySQL access for cPanel users.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store