SQL Injection Vulnerability in cPanel Database Management
CVE-2026-58048

9.4CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
31 July 2026

What is CVE-2026-58048?

The vulnerability allows an attacker to execute arbitrary SQL commands in the root context due to insufficient handling of SQL mode settings during database renaming operations in cPanel. This could potentially lead to unauthorized access and manipulation of sensitive data within the database. Proper measures should be taken to ensure that SQL mode is correctly preserved to mitigate risks associated with privilege escalation.

Affected Version(s)

cPanel 11.110.0.137

cPanel 11.126.0.78

cPanel 11.134.0.48

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincent55 Yang
.