cPanel disclosed and patched CVE-2026-58048, a critical privilege-escalation flaw in cPanel & WHM that allows an authenticated user with MySQL or MariaDB access to execute arbitrary SQL commands with full database administrator privileges. The bug, rated CVSS 9.4, affects all supported cPanel & WHM versions and WP Squared, and stems from the database rename process failing to preserve SQL mode correctly, enabling escalation into the database root context.
The company warned that in some shared-hosting, database, and operating-system configurations, the flaw could extend beyond database control to OS-level compromise and potentially full server takeover. cPanel said customers should upgrade immediately to fixed releases; if patching is delayed, administrators should temporarily revoke the MySQL feature from cPanel users and review database audit logs for suspicious administrative activity. CISA said no active exploitation had been observed and classified the issue as non-automatable despite its severe technical impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On August 4, CISA listed CVE-2026-58048 with no observed exploitation, classified it as non-automatable, and rated its technical impact as total. This status update accompanied public reporting on the newly disclosed cPanel vulnerability.
cPanel released fixed builds for all supported cPanel & WHM versions and WP Squared/WP2 deployments, including 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and 138.1.6. The flaw allows an authenticated user with MySQL or MariaDB access to execute arbitrary SQL commands with full database administrative privileges.
WebPros credited security researcher Vincent55 Yang with responsibly reporting the cPanel & WHM privilege-escalation flaw CVE-2026-58048. The references do not provide a date for when the report was made.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.