HackerFeeds

CyberSecurity News

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

The Hacker News
· August 4, 2026

AI summary

A critical flaw in cPanel has been patched, which previously allowed an authenticated hosting customer to execute SQL commands with database root privileges. This vulnerability crossed the privilege boundary between a cPanel account and the server's administrative database identity. The issue is tracked as CVE-2026-58048 with a CVSS score of 9.4, indicating a high severity. The patch was released as part of a targeted security update that also addressed two other issues related to account boundaries. The vulnerability affected cPanel, although the specific versions or configurations impacted are not specified. The fix prevents hosting customers from gaining unauthorized access to the database.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.