CVE-2026-58048 – cPanel
CVSS 9.4
CRITICAL
Critical - Same Day Deployment
“A database rename operation can expose cPanel systems to SQL execution with root-level context.”
CVE-2026-58048 is a Critical SQL injection vulnerability affecting cPanel. Improper preservation of SQL mode during database rename operations can allow SQL to execute in root context. The CVSS score is 9.4, which is Critical severity.
The cPanel security update addresses the database-handling flaw and prevents the vulnerable SQL execution path.
Key Details
- CWE Classification
- CWE-89
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.