top of page
perceptive_background_267k.jpg

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Published:

4 August 2026 at 12:36:27

Alert date:

4 August 2026 at 14:01:53

Source:

thehackernews.com

Click to open the original link from this advisory

Web Technologies, Database & Storage, Identity & Access

cPanel has patched a critical vulnerability tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4. The flaw allowed an authenticated hosting customer to execute SQL commands in the database's root context, effectively crossing the privilege boundary between a cPanel account and the server's administrative database identity. This represents a severe privilege escalation issue affecting shared hosting environments. The fix was shipped in a targeted security release that also closes two additional routes past account boundaries. The vulnerability poses significant risk to hosting providers and their customers, as exploitation could allow unauthorized access to all databases managed by the server's root database user.

Technical details

Mitigation steps:

Affected products:

cPanel

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page