CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

cPanel Patches Critical SQL Injection Flaw Allowing Database Root Access

August 4, 2026

cPanel has released a targeted security update to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands with database root privileges. The flaw, tracked as CVE-2026-58048 with a CVSS score of 9.4, affects all supported versions of cPanel & WHM and WP Squared. It stems from a failure in the database-renaming process where SQL mode is not preserved, causing SQL to run in the administrative root context. This could potentially lead to operating-system-level compromise depending on the configuration.

The update also patches two other vulnerabilities: CVE-2026-58047, an HTTP request-smuggling issue in cpsrvd that could leak credentials, and GCVE-25-2026-07-45-3, an Exim flaw allowing privilege escalation via .forward files. Additionally, Exim 4.99.5 fixes GCVE-25-2026-07-45-1, a high-severity directory traversal issue.

cPanel recommends immediate patching to the specified builds. For servers that cannot update right away, administrators can temporarily revoke the MySQL feature from cPanel users or disable backend connection reuse for the request-smuggling issue. CISA’s assessment notes no known exploitation yet, but the technical impact is rated as total.

CVEs: CVE-2026-58048, CVE-2026-58047, CVE-2026-50522

Companies: cPanel, CISA, HackerOne

Products: cPanel & WHM, WP Squared, Exim