Ethical Hacking News
A critical security flaw has been discovered in cPanel, allowing authenticated users to execute SQL as root with full database administrator access. CVE-2026-58048 has significant implications for shared hosting boxes and servers running cPanel & WHM. Users are advised to update to fixed versions of cPanel & WHM and follow best practices for securing sensitive data.
CVE-2026-58048 is a critical cPanel bug allowing authenticated users to execute SQL as root with full database administrator access.The bug was reported by researcher Vincent55 Yang and initially classified as a privilege escalation, but also described as an SQL injection vulnerability (CWE-89).Severity score of 9.4 indicates high impact on security.Exploitation status: currently unknown but rated as total, implying significant technical impact.Patch available in updated versions of cPanel & WHM and by temporarily revoking the "MySQL" feature.
CVE-2026-58048, a critical cPanel bug, has been identified and exposed, allowing authenticated users to execute SQL as root with full database administrator access. This vulnerability has significant implications for shared hosting boxes and servers running cPanel & WHM.
The bug was reported by researcher Vincent55 Yang and was initially classified as a privilege escalation, although it can also be described as an SQL injection vulnerability (CWE-89). The issue lies in the way cPanel renames databases, which leads to a incorrect preservation of SQL mode, allowing commands to execute with root-level authority instead of limited privileges.
The severity score of this bug is 9.4, indicating that it has a high impact on security. According to US CISA, exploitation status for this vulnerability is currently none observed, but it's still rated as total, implying that the technical impact is significant even if the exploit hasn't been tried yet.
To patch this issue, users can update to fixed versions of cPanel & WHM, which include builds 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and 138.1.6 for WP Squared. As a stopgap measure, users can temporarily revoke the "MySQL" feature from cPanel users to prevent adding or removing databases.
This vulnerability highlights the importance of regular software updates and security patches. cPanel users should prioritize updating their systems to the latest versions and following best practices for securing sensitive data.
Related Information:
https://www.ethicalhackingnews.com/articles/Cpanel-Security-Flaw-A-Critical-Vulnerability-Exposed-by-CVE-2026-58048-ehn.shtml
https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html
https://nvd.nist.gov/vuln/detail/CVE-2026-58048
https://www.cvedetails.com/cve/CVE-2026-58048/
Published: Tue Aug 4 09:08:09 2026 by llama3.2 3B Q4_K_M