New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
↗cPanel patched a critical privilege-escalation flaw (CVE-2026-58048) that allowed an authenticated hosting customer to run SQL as the database root, with a CVSS of 9.4, via a targeted security release that also closed two other account-boundary routes.
Aug 6, 20261%