Security
cPanel patches critical flaw allowing authenticated users to execute SQL as database root
Image: Primary cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context. The database bug is tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4 and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.
Sources
Evidence entered
Admission Evidence and chronology passed Security
Accepted draft cycle
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context. The database bug is tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4 and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there,
16 s recorded draft · 1.5 s provider time Publication receipt Entered the validated Newswire
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire