🔴 Critical | Source: The Hacker News
A critical vulnerability in cPanel (CVE-2026-58048, CVSS 9.4) allows an authenticated hosting customer to execute SQL commands with database root privileges, effectively bypassing the isolation boundary between a standard cPanel account and the server’s administrative database identity. This is particularly serious in shared hosting environments where multiple customers reside on the same server, as exploitation could expose or manipulate data belonging to other tenants or the host itself. cPanel has issued a targeted security release addressing this flaw alongside two further privilege boundary bypasses.
Security Architect’s Take: Ensure all cPanel installations are patched to the latest targeted security release immediately, prioritising any shared hosting infrastructure where the tenant isolation boundary is the primary control separating customer workloads. Review hosting provider patch status if cPanel underpins any managed or shared infrastructure in your supply chain.
Original advisory: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root