Volver a los avisos de seguridad

Security: CVE-2026-58048 Database Privilege Escalation

A privilege escalation vulnerability exists in cPanel & WHM's database management functionality. 

Critical 9.4 CVSS
cPanel

CMD de actualización por defecto

sudo /scripts/upcp --force

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

A privilege escalation vulnerability exists in cPanel & WHM’s database management functionality. 

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions 11.110.0.137
11.118.0.71
11.126.0.78
11.134.0.48
11.136.0.32
138.1.6 ( WP2 )

Impact

An authenticated cPanel account holder with access to the MySQL/MariaDB database feature could potentially execute arbitrary database commands with full administrative privileges. Depending on the operating system and database engine configuration, this may extend to operating-system-level compromise.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Mitigation

Servers that cannot immediately upgrade can temporarily revoke the “MySQL” feature from cPanel users. This will not disable existing databases but just prevent adding/removing. To do so, you can follow the steps here:
How to edit a feature list

Acknowledgements

WebPros thanks Vincent55 Yang for responsibly disclosing this issue.
 

Preguntas frecuentes

What is CVE-2026-58048?
A database privilege escalation in cPanel & WHM: improper preservation of SQL mode during database renames lets an authenticated cPanel account with MySQL/MariaDB access execute SQL as the database root user — in some configurations reaching the operating system itself.
Is CVE-2026-58048 being exploited in the wild?
No confirmed exploitation has been announced. Patch on your normal schedule and watch the vendor advisory for updates.
How do I fix CVE-2026-58048?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema