Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Tony40Tony40 Member

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.

Depending on the operating system and database engine configuration, “this may extend to operating-system-level compromise.”

cPanel patched CVE-2026-58048 in these builds:

11.110.0.137
11.118.0.71
11.126.0.78
11.134.0.48
11.136.0.32
138.1.6 for WP Squared

Servers that cannot update immediately can .....

https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

Thanked by 2glueckself buggedout

Comments

Sign In or Register to comment.