CVE-2026-58048
published 2026-07-31CVE-2026-58048: Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
PriorityP264critical9.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.97%
60.3th percentile
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | < 11.110.0.137 | 11.110.0.137 |
| webpros | cpanel | < 11.126.0.78 | 11.126.0.78 |
| webpros | cpanel | < 11.134.0.48 | 11.134.0.48 |
| webpros | cpanel | < 11.136.0.32 | 11.136.0.32 |
| webpros | cpanel | < 11.137.9999.99 | 11.137.9999.99 |
| webpros | cpanel | < 11.118.0.71 | 11.118.0.71 |
| webpros | wp_squared | < 11.138.1.6 | 11.138.1.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
ghsa_unreviewed·2026-07-31
CVE-2026-58048 [CRITICAL] CWE-89 Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
VulDB
WebPros cPanel/WP Squared sql injection
vuldb·2026-07-31·CVSS 9.4
CVE-2026-58048 [CRITICAL] WebPros cPanel/WP Squared sql injection
A vulnerability identified as problematic has been detected in WebPros cPanel and WP Squared. This affects an unknown function. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-58048. The attack is possible to be carried out remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
Hackernews
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
blogs_hackernews·2026-08-28
CVE-2026-65643 Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.
The vulnerability, assigned the CVE identifier CVE-2026-65643 , impacts all supported versions of cPanel & WHM.
cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server.
"Successful exploitation leads to code execution a
Hackernews
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
blogs_hackernews·2026-08-10
CVE-2026-34348 ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.
That’s only part of it. Here’s everything else that made the Monday recap.
## ⚡ Threat of the Week
Anthropic's Model Attempts to Poison Open-Source Project — A new evaluati
Hackernews
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
blogs_hackernews·2026-08-04·CVSS 9.4
CVE-2026-58048 [CRITICAL] New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From ther
2026-07-31
Published