CVE-2026-58048 — Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
CVE-2026-58048CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
HTTP Smuggling in cPanel allows potential leak of credentials.
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.