Patch released cPanel & WHM privilege-escalation WP Squared cPanel web-app
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
CVE Tools coverage
cPanel has addressed a critical vulnerability allowing authenticated users to execute SQL commands in the database root context, potentially leading to full system compromise. Tracked as CVE-2026-58048 (CVSS score 9.4), it impacts all supported versions of cPanel & WHM and WP Squared. Attackers need valid account access and MySQL/MariaDB privileges to exploit this flaw. The fix was included in several updated builds, including 11.110.0.137 and 138.1.6 for WP Squared. Administrators unable to update immediately should temporarily disable MySQL access for cPanel users.