Güvenlik Danışarlıklarına Dön

Security: CVE-2026-58048 Database Privilege Escalation

A privilege escalation vulnerability exists in cPanel & WHM's database management functionality. 

Critical 9.4 CVSS
cPanel

Varsayılan Güncelleme Komutu

sudo /scripts/upcp --force

SharedLicense lisansı altında bunun anlamı

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

A privilege escalation vulnerability exists in cPanel & WHM’s database management functionality. 

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions 11.110.0.137
11.118.0.71
11.126.0.78
11.134.0.48
11.136.0.32
138.1.6 ( WP2 )

Impact

An authenticated cPanel account holder with access to the MySQL/MariaDB database feature could potentially execute arbitrary database commands with full administrative privileges. Depending on the operating system and database engine configuration, this may extend to operating-system-level compromise.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Mitigation

Servers that cannot immediately upgrade can temporarily revoke the “MySQL” feature from cPanel users. This will not disable existing databases but just prevent adding/removing. To do so, you can follow the steps here:
How to edit a feature list

Acknowledgements

WebPros thanks Vincent55 Yang for responsibly disclosing this issue.
 

Sıkça Sorulan Sorular

What is CVE-2026-58048?
A database privilege escalation in cPanel & WHM: improper preservation of SQL mode during database renames lets an authenticated cPanel account with MySQL/MariaDB access execute SQL as the database root user — in some configurations reaching the operating system itself.
Is CVE-2026-58048 being exploited in the wild?
No confirmed exploitation has been announced. Patch on your normal schedule and watch the vendor advisory for updates.
How do I fix CVE-2026-58048?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Sisteminizi güvenlik açıkları açısından kontrol edin

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Sisteminizi Kontrol Edin