Security
cPanel patches critical flaw allowing authenticated users to execute SQL as database root
Image: Primary cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context. The database bug is tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4 and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.