HomeSecuritycPanel: Critical SQL vulnerability allows execution as root

cPanel: Critical SQL vulnerability allows execution as root

A critical vulnerability in cPanel was recently disclosed, allowing an authenticated hosting user to execute SQL with full database administrative privileges — that is, as database root. The vulnerability, tracked as CVE-2026-58048, affects all supported versions of cPanel & WHM as well as WP Squared, and is rated CVSS 4.0: 9.4 — one of the highest severity ratings. cPanel has released a targeted security update that closes this vulnerability along with two other account limit violations.

See also: Meshtastic: Critical GitHub Actions flaw with pull_request_target allows supply chain compromise (CVE-2026-44359)

cPanel critical vulnerability CVE-2026-58048 SQL injection database root

The issue is in database rename . According to the HackerOne CNA, when renaming a database, the SQL mode, resulting in SQL commands being executed in the database manager context. The normal cPanel workflow creates a new database, migrates the original data, recreates the grants and cached code, and then deletes the old database. At this point in the flow, the failure to preserve SQL mode opens the window for exploitation.

CISA listed the vulnerability on August 4th with the tag “Exploitation: none , ” rating it as non-automated, but with a technical impact of: global . This means that while no active exploit has been documented , successful exploitation of the vulnerability could lead to a full database compromise — and, depending on the operating system and MySQL/MariaDB configuration , potentially an operating system-level compromise.

CVE-2026-58048: Technical details of the cPanel vulnerability

The vulnerability CVE-2026-58048 is classified as CWE-89 (SQL Injection), although the official cPanel describes it as privilege escalation without using the term SQL injection. The two descriptions refer to the same error from different perspectives. To exploit the vulnerability, one needs a valid cPanel and access to the MySQL/MariaDB. With these conditions, the account holder can execute arbitrary database commands with full administrative privileges.

The affected versions of cPanel & WHM include branches fixed in versions 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48 , and 11.136.0.32. For WP Squared, the fix is ​​included in version 11.138.1.6. The update can be done through WHM or using the command documented by cPanel. For servers that cannot be updated immediately, administrators can temporarily remove MySQL from cPanel users — this allows existing databases to continue to function, but prevents users from adding or removing databases.

It's worth noting that the severity of the vulnerability also depends on the deployment environment. A server hosting accounts for a single company presents a different risk profile than a shared hosting server selling accounts to unknown users. However, as security experts point out, accounts can be compromised through phishing or resold, so this distinction does not significantly reduce the risk.

See also: Adobe Campaign Classic: Critical CVSS 10.0 vulnerability allows unauthenticated code execution (CVE-2026-48449)

cPanel: Critical SQL vulnerability allows execution as root

Two additional cPanel vulnerabilities in the same security update

The same cPanel security update addresses two other vulnerabilities. CVE-2026-58047 ( CVSS 4.0:5.6 ) concerns an HTTP request smuggling issue in cpsrvd , the daemon that serves the cPanel and WHM interfaces. Under limited circumstances, an unauthenticated remote attacker could manipulate responses delivered to other users of the same server, potentially leaking credentials. cPanel credits researcher Vincent55 Yang for discovering both CVEs .

For those who cannot immediately apply the update for CVE-2026-58047 , the temporary workaround is to disable backend connection reuse by setting cpsrvd_keepalives_disabled=1 in the /var/cpanel/cpanel.config file and restarting cpsrvd . This workaround forces a new TCP and TLS connection for each request on ports 2083 , 2087 , and 2096 , which can increase latency and CPU usage on busy servers. The third vulnerability, GCVE-25-2026-07-45-3 , affects Exim and is related to unsafe string expansion via a local user .forward file , which can lead to privilege escalation by Team User subaccounts .

The historical context of this disclosure is troubling. In April 2026, CVE-2026-41940 in cPanel & WHM was described as an unauthenticated authentication bypass that could grant full administrative access. Rapid7 estimated at the time that approximately 1.5 million cPanel instances exposed online were vulnerable. In parallel, CVE-2026-57517 in Control Web Panel (CWP) was a critical SQL injection vulnerability that allowed SQL execution as MySQL root and, due to the global FILE privilege, possible remote code execution. The pattern is clear: attackers target control-plane software because a single flaw can affect multiple tenants or entire servers at once.

Security experts emphasize that the root cause is not simply inadequate input filtering, but a privilege threshold failure in the way the rename flow maintains SQL mode. This means that a simple WAF would not be a permanent solution. Successful exploitation allows the creation of privileged database users, modification or corruption of data, and potentially manipulation of the database configuration at the server level.

See also: CISA: Vulnerability in LiteSpeed ​​cPanel Plugin allows privilege escalation

cPanel: Critical SQL vulnerability allows execution as root

For administrators using cPanel on Greek and European hosting infrastructures, the recommendations are clear: update immediately to the first patched version for your industry, verify the exact installed version before applying the patch, and monitor database renaming and permission change activity for any suspicious usage. Additionally, it is recommended to check database users and grants for unauthorized privileged accounts, rotate credentials, and assess data integrity for databases that may have been exposed. The vulnerability has not yet been publicly exploited, but its critical nature requires immediate action by all administrators using the software.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS