cPanel and WebPros: Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

cPanel and WebPros: Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise

A severe vulnerability in cPanel & WHM (CVE-2026-58048) has been disclosed, allowing authenticated users to execute arbitrary SQL commands with full database administrative privileges. The flaw, which affects the platform’s database management functionality, could lead to root-level server compromise in certain configurations, particularly in shared hosting environments.

Key Details

  • Who: The vulnerability impacts all supported versions of cPanel & WHM prior to patched releases.
  • What: An authenticated attacker with access to the MySQL or MariaDB feature can escalate privileges, bypassing assigned permissions to execute administrative SQL commands.
  • Impact: Successful exploitation could enable attackers to:
    • Access or exfiltrate sensitive customer databases.
    • Modify database users and permissions.
    • Extract credentials or deploy malicious triggers.
    • Gain filesystem access, potentially leading to full server compromise.
  • Where: The risk is highest in shared hosting environments, where multiple users share the same server.
  • When: The flaw was disclosed by WebPros, with credit to security researcher Vincent55 Yang. No technical exploitation details have been publicly released.

Mitigation & Patching

cPanel has released patched versions to address the issue:

  • 11.110.0.137
  • 11.118.0.71
  • 11.126.0.78
  • 11.134.0.48
  • 11.136.0.32
  • 138.1.6 (for WP2 deployments)

For administrators unable to patch immediately, a temporary mitigation involves revoking the MySQL feature from affected cPanel users via feature list management. Security teams are advised to review database audit logs for suspicious activity, such as unauthorized privilege assignments or unusual file-related operations.

Hosting providers should prioritize patching, as the severity of the flaw makes rapid remediation critical.

Source: https://cybersecuritynews.com/cpanel-vulnerability/

cPanel TPRM report: https://www.rankiteo.com/company/cpanel

WebPros TPRM report: https://www.rankiteo.com/company/webpros

"id": "webcpa1785839895",
"linkid": "webpros, cpanel",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'All users of supported versions '
                                              'prior to patched releases',
                        'industry': 'Web Hosting, IT Infrastructure',
                        'name': 'cPanel & WHM',
                        'type': 'Software/Platform'}],
 'attack_vector': 'Authenticated access to MySQL/MariaDB feature',
 'data_breach': {'data_exfiltration': 'Potential',
                 'personally_identifiable_information': 'Potential',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Customer databases',
                                              'Credentials']},
 'description': 'A severe vulnerability in cPanel & WHM (CVE-2026-58048) has '
                'been disclosed, allowing authenticated users to execute '
                'arbitrary SQL commands with full database administrative '
                'privileges. The flaw could lead to root-level server '
                'compromise in certain configurations, particularly in shared '
                'hosting environments.',
 'impact': {'data_compromised': 'Sensitive customer databases, credentials, '
                                'payment information risk',
            'identity_theft_risk': 'Yes',
            'operational_impact': 'Potential full server compromise, '
                                  'unauthorized database modifications',
            'payment_information_risk': 'Yes',
            'systems_affected': 'cPanel & WHM servers (shared hosting '
                                'environments)'},
 'post_incident_analysis': {'corrective_actions': 'Patch deployment, feature '
                                                  'revocation, log monitoring',
                            'root_causes': 'Privilege escalation flaw in '
                                           "cPanel & WHM's database management "
                                           'functionality'},
 'recommendations': 'Prioritize patching, revoke MySQL feature for affected '
                    'users if patching is delayed, review database audit logs '
                    'for suspicious activity.',
 'references': [{'source': 'WebPros'}],
 'response': {'containment_measures': 'Revoking MySQL feature from affected '
                                      'cPanel users via feature list '
                                      'management',
              'enhanced_monitoring': 'Review database audit logs for '
                                     'suspicious activity',
              'remediation_measures': 'Patching to fixed versions '
                                      '(11.110.0.137, 11.118.0.71, '
                                      '11.126.0.78, 11.134.0.48, 11.136.0.32, '
                                      '138.1.6)'},
 'title': 'Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers '
          'to Root-Level Compromise',
 'type': 'Privilege Escalation',
 'vulnerability_exploited': 'CVE-2026-58048'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.