cbcvebase.
CVE-2026-58048
published 2026-07-31

CVE-2026-58048: Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

PriorityP264critical9.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.97%
60.3th percentile
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Affected

7 ranges
VendorProductVersion rangeFixed in
webproscpanel< 11.110.0.13711.110.0.137
webproscpanel< 11.126.0.7811.126.0.78
webproscpanel< 11.134.0.4811.134.0.48
webproscpanel< 11.136.0.3211.136.0.32
webproscpanel< 11.137.9999.9911.137.9999.99
webproscpanel< 11.118.0.7111.118.0.71
webproswp_squared< 11.138.1.611.138.1.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.