What is CVE-2026-58048?
A critical flaw in cPanel allowed an authenticated hosting customer to execute SQL in the database's root context, bypassing the privilege boundary between a cPanel account and the server's administrative database identity. cPanel has patched this issue in a targeted security release, which also addresses two other privilege escalation paths.
Azərbaycanca: cPanel proqramında autentifikasiya olunmuş hostinq müştərisinə verilənlər bazası üzərində root kontekstində SQL sorğuları icra etməyə imkan verən kritik zəiflik aşkarlanıb. Bu boşluq müştəri hesabı ilə serverin inzibati verilənlər bazası identifikasiyası arasındakı imtiyaz sərhədini aşır. cPanel artıq bu problemi hədəflənmiş təhlükəsizlik yeniləməsi ilə aradan qaldırıb.
Related CVEs
link basis: same weakness class CWE-89
FAQ1
What privileged operation can be performed by exploiting CVE-2026-58048?
This flaw allows an authenticated hosting customer to execute SQL in the database's root context.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.