logo

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

ID: 44773dca-76e5-5bce-8182-a5a918a88894

STIX ID: report--44773dca-76e5-5bce-8182-a5a918a88894

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: [email protected] (The Hacker News)

...
...

cPanel published targeted security updates addressing a high-severity database privilege-escalation vulnerability (CVE-2026-58048, CVSS 9.4) that allows an authenticated cPanel user with MySQL/MariaDB access to run arbitrary SQL in the database administrative context and potentially achieve operating-system-level compromise; the advisory lists patched builds and a temporary mitigation (revoking the MySQL feature) and also fixes CVE-2026-58047 (HTTP request smuggling in cpsrvd) plus multiple Exim GCVE issues, while CISA noted no known exploitation at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.