Dossier
CVE-2026-58048
Coverage of CVE-2026-58048 in the Nexus archive.
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a critical flaw allowing authenticated hosting customers to execute SQL in the database's root context, bypassing privilege boundaries between accounts and the server's administrative database. The vulnerability, tracked as CVE-2026-58048 with a CVSS score of 9.4, was addressed in a targeted security release that also fixed two additional account boundary vulnerabilities.