Skip to main content
Back to Newswire
Security

cPanel patches critical flaw allowing authenticated users to execute SQL as database root

cPanel patches critical flaw allowing authenticated users to execute SQL as database root Image: Primary
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context. The database bug is tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4 and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.