cPanel Fixes Critical Flaw Allowing Hosting Customers to Run SQL as Database Root
cPanel has released a targeted security update addressing a critical vulnerability that allowed an authenticated hosting account holder to run SQL commands in the context of the database's root user. This crosses a key privilege boundary between an individual cPanel account and the server's administrative database identity, meaning a low-level user could potentially gain far greater control over the underlying database system than intended.
The flaw, tracked as CVE-2026-58048, carries a high severity rating with a CVSS 4.0 score of 9.4, reflecting the serious risk it poses if exploited. The same security release also closes two additional issues that could allow users to bypass account boundaries, though details on these were not fully specified. cPanel is widely used by web hosting providers, including many that serve Australian small businesses, making this patch relevant to any business running a website or email through a cPanel-based host.
While there is no indication in current reporting that this vulnerability has been exploited in the wild, critical flaws affecting shared hosting environments are attractive targets for attackers, as a single exploit could potentially affect multiple customers on the same server. Businesses that manage their own hosting infrastructure, or use a provider that relies on cPanel, should treat this as a priority update.