cPanel has released security updates to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands using the database root context, effectively bypassing the privilege boundaries between standard cPanel accounts and the server administrative database identity. The flaw, tracked as CVE 2026 58048 with a CVSS 4.0 score of 9.4, affects all supported versions of cPanel and WHM as well as WP Squared. According to the company, exploitation requires a valid cPanel account with access to MySQL or MariaDB features. Once those conditions are met, an attacker could execute arbitrary database commands with full administrative privileges. cPanel also warned that, depending on the operating system and database configuration, the vulnerability could potentially lead to operating system level compromise. Security updates have been released in versions 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and version 138.1.6 for WP Squared.
According to cPanel, the vulnerability originates from the database renaming process, where SQL mode is not preserved during database renaming, resulting in SQL statements being executed under the database root context. Under normal conditions, cPanel limits database users to privileges that do not require SUPER permissions or allow global modifications. However, CVE 2026 58048 bypasses those restrictions by allowing SQL execution with administrative privileges. The company advisory classifies the issue as a privilege escalation vulnerability, while the HackerOne CNA record categorizes it under CWE 89, commonly associated with SQL injection. Although both records describe the same flaw, they approach its classification differently. Neither advisory identifies the exact SQL payload, injected input, or affected SQL mode responsible for triggering the issue. Questions also remain regarding whether Team User subaccounts with database access fall within the definition of authenticated account holders capable of exploiting the vulnerability. For organizations unable to apply updates immediately, cPanel recommends temporarily revoking the MySQL feature from user accounts. This measure prevents database creation and deletion while allowing existing databases to remain operational until updates can be installed through WHM or by executing the documented update command.
In the same security release, cPanel addressed CVE 2026 58047, an HTTP request smuggling vulnerability affecting cpsrvd, the service responsible for delivering cPanel and WHM interfaces. Assigned a CVSS 4.0 score of 5.6, the flaw could allow an unauthenticated remote attacker, under limited conditions, to manipulate responses sent to other users sharing the same server. According to the CNA record, successful exploitation could expose user credentials. Administrators unable to update immediately can reduce the risk by disabling backend connection reuse through the cpsrvd configuration, although cPanel noted that doing so increases CPU utilization and network latency because each request requires a separate TCP and TLS connection. The company credited security researcher Vincent55 Yang with reporting both CVE 2026 58048 and CVE 2026 58047. Meanwhile, the United States Cybersecurity and Infrastructure Security Agency recorded that no exploitation had been observed as of August 4 and assessed the flaw as nonautomatable while rating its potential technical impact as total.
The security release also includes updates for vulnerabilities affecting the Exim mail transfer agent. One advisory addresses GCVE 25 2026 07 45 3, where a local user .forward file could trigger unsafe string expansion within the redirect router under certain pipe transport configurations. Under the default cPanel configuration, execution occurs as the cPanel user and could allow privilege escalation from Team User subaccounts. Exim version 4.99.5 removes the vulnerable behavior while also fixing GCVE 25 2026 07 45 1, a high severity local directory traversal vulnerability involving queue name command line arguments that could allow access to files outside the spool directory and potentially lead to privilege escalation. Researchers also noted inconsistencies between cPanel advisories regarding patched builds. While the database advisory lists version 11.118.0.71 as containing the fix, the advisories covering the HTTP request smuggling and Exim vulnerabilities omit the 11.118 branch entirely. Administrators using that release are therefore advised to verify the installed version against the database advisory rather than relying solely on the abbreviated patch lists. The Exim advisories do not identify an individual researcher and instead credit unnamed and uncredited authors whose works were ingested as the training corpus.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





