CVE-2026-58047
published 2026-07-31CVE-2026-58047: HTTP Smuggling in cPanel allows potential leak of credentials.
PriorityP430medium5.6CVSS 4.0
AVNACLATPPRNUIPVCLVILVANSCHSIHSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.53%
44.1th percentile
HTTP Smuggling in cPanel allows potential leak of credentials.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | < 11.110.0.137 | 11.110.0.137 |
| webpros | cpanel | < 11.126.0.78 | 11.126.0.78 |
| webpros | cpanel | < 11.134.0.48 | 11.134.0.48 |
| webpros | cpanel | < 11.136.0.32 | 11.136.0.32 |
| webpros | cpanel | < 11.137.9999.99 | 11.137.9999.99 |
| webpros | cpanel | < 11.118.0.71 | 11.118.0.71 |
| webpros | wp_squared | < 11.138.1.6 | 11.138.1.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
HTTP Smuggling in cPanel allows potential leak of credentials.
ghsa_unreviewed·2026-07-31
CVE-2026-58047 [MEDIUM] CWE-444 HTTP Smuggling in cPanel allows potential leak of credentials.
HTTP Smuggling in cPanel allows potential leak of credentials.
VulDB
WebPros cPanel/WP Squared input validation
vuldb·2026-07-31·CVSS 5.6
CVE-2026-58047 [MEDIUM] WebPros cPanel/WP Squared input validation
A vulnerability labeled as critical has been found in WebPros cPanel and WP Squared. This impacts an unknown function. Executing a manipulation can lead to improper input validation.
This vulnerability appears as CVE-2026-58047. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
Hackernews
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
blogs_hackernews·2026-08-28
CVE-2026-65643 Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.
The vulnerability, assigned the CVE identifier CVE-2026-65643 , impacts all supported versions of cPanel & WHM.
cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server.
"Successful exploitation leads to code execution a
Hackernews
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
blogs_hackernews·2026-08-04·CVSS 9.4
CVE-2026-58048 [CRITICAL] New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From ther
2026-07-31
Published