Security: CVE-2026-58048 Database Privilege Escalation
A privilege escalation vulnerability exists in cPanel & WHM's database management functionality.
Default Update CMD
sudo /scripts/upcp --force
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.
Situation
A privilege escalation vulnerability exists in cPanel & WHM’s database management functionality.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions | 11.110.0.137 11.118.0.71 11.126.0.78 11.134.0.48 11.136.0.32 138.1.6 ( WP2 ) |
Impact
An authenticated cPanel account holder with access to the MySQL/MariaDB database feature could potentially execute arbitrary database commands with full administrative privileges. Depending on the operating system and database engine configuration, this may extend to operating-system-level compromise.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Mitigation
Servers that cannot immediately upgrade can temporarily revoke the “MySQL” feature from cPanel users. This will not disable existing databases but just prevent adding/removing. To do so, you can follow the steps here:
How to edit a feature list
Acknowledgements
WebPros thanks Vincent55 Yang for responsibly disclosing this issue.
Frequently Asked Questions
What is CVE-2026-58048?
Is CVE-2026-58048 being exploited in the wild?
How do I fix CVE-2026-58048?
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System