CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical SQL Injection in cPanel Database Renaming

August 4, 2026

CVE-2026-58048 is a critical SQL injection vulnerability in cPanel & WHM and WP Squared, allowing authenticated hosting customers to execute arbitrary SQL commands with database root privileges. The flaw arises from a failure to preserve SQL mode during database renaming, leading to privilege escalation. It has a CVSS score of 9.4 and could potentially lead to OS-level compromise.