CRITICAL
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel patched a flaw, tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4), that let an authenticated hosting customer execute SQL in the database’s root context, crossing the boundary between a standard cPanel account and the server’s administrative database identity.
The fix shipped in a targeted security release that also closed two other account-boundary bypass routes. Hosting providers running cPanel should apply the update promptly given the low bar for exploitation — any authenticated customer account.