
cPanel Releases Critical Security Patch for Privilege Escalation Flaw (CVE-2026-58048)
CybersecurityVulnerabilitiesPrivilegeEscalationDatabaseSecurity
cPanel released a security patch addressing a critical flaw (CVE-2026-58048) with a CVSS 4.0 score of 9.4, allowing authenticated hosting customers to execute SQL commands with database root privileges. The vulnerability breached privilege boundaries between a cPanel account and the server’s administrative database identity. The fix was included in a targeted security release that also closed two additional privilege escalation routes. No specific affected versions or exploitation details were disclosed in the notice. The flaw enables unauthorized database access at the highest administrative level.