logo

CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access

ID: e0220431-1102-52ce-9a12-8b209ed5243f

STIX ID: report--e0220431-1102-52ce-9a12-8b209ed5243f

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: Pierluigi Paganini

...
...

CVE-2026-58048 is a critical cPanel/WHM and WP Squared vulnerability (CVSS 9.4) that allows any authenticated cPanel account with MySQL/MariaDB access to execute arbitrary SQL as the database root — potentially enabling full database administration and, depending on configuration, operating-system compromise; cPanel has issued patches for all supported builds and suggests temporarily revoking the MySQL feature for users who cannot immediately upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.