# cPanel patches critical flaw allowing authenticated users to execute SQL as database root

_Tuesday, August 4, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![cPanel patches critical flaw allowing authenticated users to execute SQL as database root — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2LFB09rf16kl1_PinOnHkAY4GiI38_azQ2t-EWYRicFndp5DX-5KSfwVVEJxwEKp07oouBfkFg71MxwilLY_M2i3clk82hs5-Xr-PgDj69JeYzTsPjp_8sdNZIminQFonHRq2GqWDXJuwGqpT4Na485_pILlvMSlBdSMqWYWqTHDrUC_9OdOW-kCdSeM/s1700-e365/cpanel.jpg)

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context. The database bug is tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4 and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html)

---
Canonical: https://techandbusiness.org/newswire/6k0CmPJVStz8khkW34O4HM
Retrieved: 2026-08-04T15:59:14.929Z
Publisher: Tech & Business (techandbusiness.org)
