New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- ID
- 10663
- Status
- summarized
- Published
- 04 Aug 2026, 6:36 PM
- Fetched
- 04 Aug 2026, 8:28 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects
Summary
No summary yet. It will appear after the daemon summarizes this item.