Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A critical privilege-escalation flaw in cPanel & WHM has been disclosed that could allow authenticated hosting users to execute arbitrary SQL commands with full database administrative privileges. This vulnerability poses a risk of root-level server compromise in certain configurations.

The issue, tracked as CVE-2026-58048, affects the database management functionality within cPanel & WHM. An attacker would need a valid cPanel account and access to the MySQL or MariaDB feature to exploit this vulnerability.

This flaw is particularly concerning in shared hosting environments, where multiple customers may have accounts on the same physical or virtual server.

A low-privileged user could potentially abuse their normal database management access to execute SQL statements with database administrator privileges, rather than being limited to their own assigned permissions.

cPanel Vulnerability

According to cPanel, this vulnerability affects all supported versions of cPanel & WHM that have not yet received the vendor’s patched releases.

Depending on the operating system, database engine, and server configuration, administrative execution at the database level may be used to access the underlying operating system.

Successful exploitation of this flaw could expose sensitive customer databases, allow attackers to alter database users and permissions, extract credentials, deploy malicious database triggers, or access files through database capabilities.

In environments where MySQL or MariaDB has elevated filesystem access, the impact could extend to a complete server compromise.

Organizations affected by this vulnerability are strongly urged to update cPanel & WHM immediately to one of the patched versions: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, or 138.1.6 for WP2 deployments.

For administrators unable to patch immediately, exposure can be mitigated by revoking the MySQL feature from affected cPanel users through feature list management. This temporary measure prevents users from adding or removing databases while allowing access to existing databases.

Security teams should review database audit logs for unexpected administrative SQL activity, such as newly created database users, unusual privilege assignments, modified stored procedures, and suspicious file-related database operations.

Hosting providers should pay particular attention to accounts with recently created databases or any unexpected changes to MySQL/MariaDB permissions.

WebPros credited security researcher Vincent55 Yang for responsibly reporting this issue. The vendor has not publicly shared technical details about the exploitation.

However, the severity of the potential privilege escalation makes rapid remediation essential. Organizations operating shared cPanel infrastructure should treat CVE-2026-58048 as a high-priority patching event and verify that every managed server is running a fixed release.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.