vulnerability
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Critical
Summary
A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated hosting customers to execute arbitrary database commands with administrative privileges, potentially leading to system-wide compromise. This flaw stems from a database-renaming process that bypasses normal privilege restrictions. Two related vulnerabilities – an HTTP request smuggling issue (CVE-2026-58047) and a local directory traversal in Exim (CVE-2026-58049) – have also been patched in the same release. Immediate patching is strongly recommended.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
