news.mlab.sh
Back to the feed
vulnerability

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Critical
Image: The Hacker News
Summary

A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated hosting customers to execute arbitrary database commands with administrative privileges, potentially leading to system-wide compromise. This flaw stems from a database-renaming process that bypasses normal privilege restrictions. Two related vulnerabilities – an HTTP request smuggling issue (CVE-2026-58047) and a local directory traversal in Exim (CVE-2026-58049) – have also been patched in the same release. Immediate patching is strongly recommended.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.