Critical SEVERITY — Vulnerability

CVE-2026-58048 — Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Platform
cPanel & WHM
CVE Record
CVE-2026-58048
CVSS Score
9.4/10
Published
31 July 2026
Views
29
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Assessment

  • CVE: CVE-2026-58048
  • CVSS base score: 9.4
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

cPanel & WHM — Related Advisories

VIEW ALL →