/00 — boot sequence

Hello.

Article

cPanel CVE-2026-58048: Database Root for Any Hosting Tenant

August 9, 2026•5 min read
cpanel cve-2026-58048 privilege-escalation sql-injection shared-hosting whm

Introduction

cPanel CVE-2026-58048 is a privilege escalation in database administration patched in early August 2026, and any authenticated hosting customer can trigger it. The advisory rates the flaw 9.4 out of 10 on the CVSS scale, and the CNA record classifies it as CWE-89, the SQL injection category. In plain terms, an account holder with nothing more than a standard login and access to the MySQL or MariaDB feature can execute arbitrary database commands with full administrative privileges. Depending on the operating system and database engine configuration, the damage can extend to the operating system itself.

The issue was reported by researcher Vincent Yang through HackerOne and fixed across all supported cPanel and WHM build lines. As of August 4, CISA assesses exploitation as none observed and the flaw as non-automatable. That still leaves the technical impact as total, so shared hosting operators should treat this as a race against time rather than a waiting game.

Vulnerability Details

The root cause sits in something mundane: renaming a database. When cPanel renames one, it builds a replacement database, moves the data over, recreates the grants and stored code, then deletes the original along with its permissions. At some point in that flow, the SQL mode is not preserved correctly, so the resulting statements run in the root context instead of the limited account context.

Two details are worth flagging. First, cPanel's advisory calls the issue a privilege escalation and never uses the words SQL injection, while the CNA record files it under CWE-89. Both descriptions cover the same bug from different angles, and neither publishes the exact broken SQL mode parameter. Second, the advisory does not clarify whether Team User sub-accounts, the limited logins a reseller can hand out, count as authenticated account holders when they have database feature access. If a setup relies on delegated logins, that question belongs on a ticket to cPanel support.

Impact Assessment

This is a cross-tenant bug on a platform built for multi-tenant isolation. On a shared server, one customer could read and modify databases belonging to other customers, since database root in MySQL does not care about cPanel account boundaries. Attackers who reach that level can exfiltrate data from any site on the box, tamper with stored content, or wipe backups. On configurations where the database user maps to the operating system user, the advisory warns the escalation may climb beyond the database layer to the machine itself.

Two factors keep the situation short of a scanner-driven emergency right now: the CISA snapshot shows no observed exploitation, and the trigger needs an existing authenticated account, so the exposed population is limited to people who already hold a cPanel login. Both factors can change overnight, and cPanel servers that run with many reseller accounts widen the door.

Affected Systems and Fixed Builds

The vulnerability affects every supported version of cPanel and WHM at the time of disclosure, plus the WebPros WP Squared product. The following builds contain the fix:

ProductFixed build
cPanel11.110.0.137
cPanel11.118.0.71
cPanel11.126.0.78
cPanel11.134.0.48
cPanel11.136.0.32
WP Squared138.1.6

Builds older than the ones in the table are not fixed. Each release line must run at least the version shown for it, and the exact version string matters because the fix landed only in those specific builds.

Mitigation and Patching

The normal cPanel update path applies: run /scripts/upcp on the server or use the WHM Update to Latest Version interface. cPanel's daily update mechanism usually picks up the new builds automatically, but any server where updates are held for compatibility reasons needs an explicit release.

For servers that cannot upgrade immediately, cPanel recommends revoking the MySQL feature from cPanel users through the feature list editor. That keeps existing databases live but prevents users from adding or removing databases, which stops the vulnerable code path from being reached. It is a stopgap, not a fix.

Detection

There are no known signatures for in-the-wild exploitation yet, because none has been observed. Administrators can still look for the signs of a database rename that should not have happened: short-lived databases created and dropped in MySQL logs, grants recreated on objects the original user never touched, or stored procedures appearing in databases owned by other accounts. The MySQL general log is the place to check for statements that run with the root account outside a maintenance window, and for operations on database objects the account was never granted access to.

Frequently Asked Questions

What does CVE-2026-58048 let an attacker do?

A cPanel account holder with the MySQL feature can run arbitrary SQL with administrative privileges, which in shared hosting may expose every database on the server and, on some configurations, lead to OS access.

Do I need to be experienced or privileged to abuse this?

No. The advisory says a standard authenticated account with the MySQL or MariaDB feature is enough.

Which versions of cPanel are affected?

All supported cPanel and WHM versions released before the fixed builds listed above, plus WP Squared before 138.1.6.

Is the flaw being exploited in the wild?

CISA reported no observed exploitation as of August 4, 2026, and the same assessment marks the trigger as non-automatable.

How do I update my cPanel server?

Run /scripts/upcp from a root shell or update through WHM, and hold the update windows to make sure the server reaches one of the fixed builds.

What should I do if I cannot patch right away?

Use the stopgap from the advisory: revoke the MySQL feature from cPanel accounts through the feature list editor. This blocks new database creation and deletion, while existing sites keep running on their current databases.

Key Takeaways

  • CVE-2026-58048 is a CVSS 9.4 issue in cPanel and WHM that doubles as an SQL injection and a privilege escalation.
  • Database renaming fails to preserve the SQL mode, letting statements run with root-level database authority.
  • Every supported cPanel build line and WP Squared is affected; fixed builds are 11.110.0.137 and newer.
  • Shared hosting operators should patch immediately or revoke the MySQL feature as a stopgap.

Sources: NVD record for CVE-2026-58048 | cPanel support advisory | SecurityAffairs analysis | cPanel changelog 138

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links