Skip to content
The Nexus
SECURITYAug 4 · 10:36 UTCTHE HACKER NEWS[email protected] (The Hacker News)

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a critical flaw allowing authenticated hosting customers to execute SQL in the database's root context, bypassing privilege boundaries between accounts and the server's administrative database. The vulnerability, tracked as CVE-2026-58048 with a CVSS score of 9.4, was addressed in a targeted security release that also fixed two additional account boundary vulnerabilities.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root · The Nexus