CVE-2026-58047 — HTTP Smuggling in cPanel allows potential leak of credentials.
HTTP Smuggling in cPanel allows potential leak of credentials.
HTTP Smuggling in cPanel allows potential leak of credentials.
HTTP Smuggling in cPanel allows potential leak of credentials.
CVE-2026-58047CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.