top of page
perceptive_background_267k.jpg

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Published:

4 augustus 2026 om 10:36:27

Alert date:

4 augustus 2026 om 12:01:53

Source:

thehackernews.com

Click to open the original link from this advisory

Web Technologies, Database & Storage, Identity & Access

cPanel has patched a critical vulnerability tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4. The flaw allowed an authenticated hosting customer to execute SQL commands in the database's root context, effectively crossing the privilege boundary between a cPanel account and the server's administrative database identity. This represents a severe privilege escalation issue affecting shared hosting environments. The fix was shipped in a targeted security release that also closes two additional routes past account boundaries. The vulnerability poses significant risk to hosting providers and their customers, as exploitation could allow unauthorized access to all databases managed by the server's root database user.

Technical details

Mitigation steps:

Affected products:

cPanel

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page