cpanel-databases

A critical vulnerability in cPanel (CVE-2026-58048) allows a regular hosting account to access the databases of other customers on the same server. A fix is already available.

cPanel & WHM is the control panel used by nearly all web hosting providers—including the one that hosts your company's website. The vulnerability, assigned CVE-2026-58048, has a risk score of 9.4 out of 10 on the CVSS 4.0 scale and affects all supported versions of cPanel & WHM 11.x, as well as the WP Squared platform.

The problem arises during a routine operation: renaming a database. At that point, cPanel does not correctly preserve the “SQL mode,” and the commands end up being executed with root privileges on the MySQL or MariaDB database server. The practical consequence is that a regular hosting account, with normal access to MySQL, can run SQL commands with administrator privileges on all databases on that server, not just its own. Depending on the configuration, the researchers show that this privilege escalation can go as far as compromising the operating system.

For a small business, it’s simple: your website and database are hosted on a shared server with other customers. It doesn’t matter how well your website is built—if the server isn’t up to date, a single neighboring account—whether compromised or malicious—can gain access to your data. It’s not a problem you can fix from your own control panel.

cPanel has already released the fix. In the meantime, a proof-of-concept exploit kit has been made public, which raises the risk from theoretical to immediate for servers that have not been updated. There is, as of now, no confirmation of actual attacks exploiting this vulnerability—but the public availability of the exploit code dramatically shortens the response time.

Here's what you need to do, specifically:

  • Call or email your hosting provider and ask directly: “Do you have cPanel updated for CVE-2026-58048?” Ask for a written response.
  • If the response is delayed or evasive, treat that as a sign in itself of how the provider manages its servers.
  • Keep a copy of the database off the hosting server and update it regularly. It’s the only measure that depends entirely on you.

Sources:

This article was generated with AI assistance.

Request a quote

← All news