CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3780

As cited

Copy frozen at (site build).

vulnerabilities

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel released a security patch addressing a critical flaw (CVE-2026-58048, CVSS 9.4) that permitted authenticated hosting customers to execute SQL commands with database root privileges, bypassing privilege boundaries between customer accounts and server administration. The patch also closes two additional privilege escalation pathways. The vulnerability affected the ability to maintain proper account isolation on shared hosting infrastructure.

Why it matters: Hosting providers and their customers need to apply this patch immediately; compromised customer accounts could access or manipulate databases belonging to other customers or the hosting provider itself.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel released a security patch addressing a critical flaw (CVE-2026-58048, CVSS 9.4) that permitted authenticated hosting customers to execute SQL commands with database root privileges, bypassing privilege boundaries between customer accounts and server administration. The patch also closes two additional privilege escalation pathways. The vulnerability affected the ability to maintain proper account isolation on shared hosting infrastructure.

Why it matters: Hosting providers and their customers need to apply this patch immediately; compromised customer accounts could access or manipulate databases belonging to other customers or the hosting provider itself.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary