Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New Critical Flaw in cPanel Exposes Hosting Customers to SQL Root Privileges



A recent critical flaw in cPanel has exposed hosting customers to SQL root privileges, posing a significant threat to their data security and systems. With an extremely high CVSS score of 9.4, this vulnerability affects all supported versions of cPanel & WHM and can be exploited by authenticated users with access to the MySQL/MariaDB feature. Administrators are urged to update their systems immediately to prevent potential misuse.

  • Critical vulnerability found in cPanel, labeled as CVE-2026-58048, allowing SQL commands to be executed as database root users.
  • Vulnerability affects all supported versions of cPanel & WHM, including WP Squared.
  • Exploitation not currently occurring, but potential future attacks cannot be ruled out.
  • Admins advised to update systems and fix the issue using /usr/local/cpanel/scripts/upcp --force or WHM.



  • Threat Intelligence News
    The latest threat intelligence news and updates on vulnerabilities, exploits, and cybersecurity threats.

    cPanel has recently patched a critical flaw that allows hosting customers to run SQL commands as database root users. The vulnerability, labeled as CVE-2026-58048, was identified by the Cybersecurity and Infrastructure Security Agency (CISA) with a CVSS score of 9.4. This rating signifies an extremely high level of severity and potential impact on cPanel and WHM users.

    The critical flaw in question arises from a vulnerability in cPanel's database-renaming process, which allows SQL to execute in the root context. According to hackerone.com, the issue can cause privilege escalation by bypassing normal database-level privileges that do not require SUPER access or global modifications.

    The vulnerability is tracked as CVE-2026-58048 and affects all supported versions of cPanel & WHM, including WP Squared. To exploit this flaw, a valid cPanel account and access to the MySQL/MariaDB feature are required. Once inside, an attacker could execute arbitrary database commands with full administrative privileges.

    Depending on the operating system and database engine configuration, the vulnerability may extend to operating-system-level compromise. Fortunately, servers that cannot update immediately can temporarily revoke the MySQL feature from cPanel users, preventing them from adding or removing databases. However, this measure only leaves existing databases running without the ability to interact with new ones.

    Administrators are advised to use either WHM or a command documented by cPanel, /usr/local/cpanel/scripts/upcp --force, to update their systems and fix the issue. The CISA recorded "Exploitation: none" for this vulnerability, indicating that it is not currently being exploited in active attacks. Nonetheless, given its severity, it is crucial for administrators to act swiftly to prevent potential misuse.

    cPanel patched these critical vulnerabilities in the following builds:

    11.110.0.137
    11.118.0.71
    11.126.0.78
    11.134.0.48
    11.136.0.32
    138.1.6 for WP Squared

    For servers that cannot update immediately, disabling backend connection reuse by setting cpsrvd_keepalives_disabled=1 in /var/cpanel/cpanel.config and restarting cpsrvd can temporarily mitigate the issue. However, this workaround introduces latency and CPU use on busy servers.

    CISA's August 4 enrichment recorded "Exploitation: none," assessed the flaw as non-automatable, and rated its technical impact as total. This highlights that while there is no current exploitation, it does not confirm the lack of potential future attacks.

    The third cPanel advisory covers CVE-25-2026-07-45-3 in Exim. Under certain pipe-transport configurations, a local user's .forward file can trigger unsafe string expansion in the redirect router, allowing for privilege escalation from Team User sub-accounts.

    cPanel credits Vincent55 Yang with reporting both CVEs.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-Critical-Flaw-in-cPanel-Exposes-Hosting-Customers-to-SQL-Root-Privileges-ehn.shtml

  • https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

  • https://cybersecuritynews.com/cpanel-vulnerability/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-58048

  • https://www.cvedetails.com/cve/CVE-2026-58048/

  • https://nvd.nist.gov/vuln/detail/CVE-25-2026-07-45-3

  • https://www.cvedetails.com/cve/CVE-25-2026-07-45-3/


  • Published: Tue Aug 4 07:30:18 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us