Tag: Hosting Customers

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
News

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

A vulnerability that allowed an authenticated hosting client to run SQL in the root context of the database, bridging the privilege gap between a cPanel account and the server's administrative database identity, has been fixed by cPanel. Two additional paths beyond account boundaries are blocked by the targeted security release that was issued. The database flaw, known as CVE-2026-58048 (CVSS 4.0 score: 9.4), affects WP Squared and all supported versions of cPanel and WHM. Access to the MySQL/MariaDB functionality and a working cPanel account are prerequisites for reaching it. The seller then claims that the account holder might use full administrative rights to execute any database commands. This could include compromise at the operating system level, depending on the database engi...