CVE-2026-58048 is a critical SQL injection vulnerability in cPanel & WHM and WP Squared, allowing authenticated hosting customers to execute arbitrary SQL commands with database root privileges. The flaw arises from a failure to preserve SQL mode during database renaming, leading to privilege escalation. It has a CVSS score of 9.4 and could potentially lead to OS-level compromise.