


Perceptive Security
SOC/SIEM Consultancy

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Published:
4 augustus 2026 om 12:36:27
Alert date:
4 augustus 2026 om 14:01:53
Source:
thehackernews.com
Web Technologies, Database & Storage, Identity & Access
cPanel has patched a critical vulnerability tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4. The flaw allowed an authenticated hosting customer to execute SQL commands in the database's root context, effectively crossing the privilege boundary between a cPanel account and the server's administrative database identity. This represents a severe privilege escalation issue affecting shared hosting environments. The fix was shipped in a targeted security release that also closes two additional routes past account boundaries. The vulnerability poses significant risk to hosting providers and their customers, as exploitation could allow unauthorized access to all databases managed by the server's root database user.
Technical details
Mitigation steps:
Affected products:
cPanel
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
