TL;DR: cPanel patched a cPanel root SQL execution flaw tracked as CVE-2026-58048, rated CVSS 9.4. A second, lower-severity bug, CVE-2026-58047, allows HTTP request smuggling under limited conditions.
- Product: WebPros cPanel
- Vulnerabilities: 2 flaws (CVE-2026-58048, CVE-2026-58047)
- Highest severity: 9.4 (Critical · CVSSv4)
- Worst impact: Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in...
- Status: No confirmed exploitation yet; patches available
- Action: Update to 11.110.0.137, 11.126.0.78, 11.134.0.48, 11.136.0.32 (+3) now
| CVE | CVSS (CVSSv4) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-58048 | 9.4 | 11.110.0.137, 11.126.0.78, 11.134.0.48 (+4) | Not exploited |
| CVE-2026-58047 | 5.6 | 11.110.0.137, 11.126.0.78, 11.134.0.48 (+4) | Not exploited |
Why it matters
An independent vulnerability database describes the flaw as rooted in improper handling of SQL mode settings during database renaming operations. That gap allows a cPanel root SQL execution path that bypasses normal privilege limits entirely.
An authenticated cPanel account holder with MySQL or MariaDB access could run arbitrary database commands with full administrative privileges. Depending on the server setup, this may extend to operating-system-level compromise.
Shared hosting environments face the highest exposure here. Many hosting customers hold cPanel accounts without needing or expecting root-level database access, which makes this cPanel root SQL execution bug especially concerning for providers running multi-tenant servers.
How the attacks work
CVE-2026-58048 stems from the database rename function failing to preserve its intended SQL execution context. This opens a cPanel root SQL execution path for otherwise limited users. Separately, CVE-2026-58047 affects the cpsrvd web server component, letting an unauthenticated attacker manipulate responses sent to other users on the same server under limited conditions.
Exploitation status
No public proof-of-concept or in-the-wild exploitation has been confirmed for either CVE at this time.
Affected versions and patch
Both flaws affect all supported cPanel and WHM versions. Patched builds include 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and 138.1.6 for WP2. Administrators who cannot upgrade immediately can revoke the MySQL feature from cPanel users as a stopgap against the root SQL execution bug, and consult cPanel’s support articles for the request-smuggling workaround.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.