CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

HTTP Request Smuggling in cPanel cpsrvd

August 4, 2026

CVE-2026-58047 is an HTTP request-smuggling vulnerability in cPanel's cpsrvd daemon. Under limited conditions, an unauthenticated remote attacker could manipulate responses delivered to other users, potentially leaking credentials. The issue is rated with a CVSS score of 5.6 and can be mitigated by disabling backend connection reuse.