Our takecPanel fixed CVE-2026-58048, letting authenticated hosting customers run SQL as DB root (CVSS 9.4). Update to the listed builds now.Cyber Resilience desk
Sources (2)
- hackernews · hackernews
- cccs · cccs
What this means for you — Security leader:Update cPanel to at least 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32 or 11.138.1.6 (or the WP Squared equivalent). The CVE-2026-58048 flaw lets any authenticated hosting customer run SQL commands as the database root user.
What this means for you — Lean IT orgs:If you run your own cPanel server, update it immediately to one of the patched versions listed in the advisory. Most shared-hosting customers do not need to act.
What this means for you — MSP:Audit every cPanel/WP Squared instance you manage and push the security releases (11.110.0.137+, 11.118.0.71+, etc.). This crosses the account-to-root-database boundary and affects multiple branches.
What this means for you — Researcher:cPanel released a targeted security update fixing CVE-2026-58048 (CVSS 9.4), an authenticated SQL injection that executes as database root. It was shipped alongside two other account-boundary fixes.