New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root 17%

By Swati Khandelwal20%

8/4/2026, 3:36:00 AM

BS Summary: This article contains 16 faulty reasoning types, including Attempt to Sell a Product or Service, Unattributed Quote, and Appeal to Authority, with Negativity Bias as the most egregious example at 14.6% saturation with 113 hits. Analysis detected 838 faulty-reasoning hits from 772 analyzed words, generating a BS Score of 24.8% and a BS Rank of 17% (25,645 of 30,584 articles). This article is better (less manipulative) than 83.90% of the article peer group.

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. 
It shipped in a targeted security release that closes two other routes past account boundaries. 
The database bug is tracked as CVE-2026-58048 (CVSS 4.0 score: 9.4) and affects all supported versions of cPanel & WHM, along with WP Squared. 
Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. 
From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges. 
Depending on the operating system and database engine configuration, “this may extend to operating-system-level compromise.” 
cPanel patched CVE-2026-58048 in these builds: 
11.110.0.137 
11.118.0.71 
11.126.0.78 
11.134.0.48 
11.136.0.32 
138.1.6 for WP Squared 
Servers that cannot update immediately can temporarily revoke the MySQL feature from cPanel users. 
That leaves existing databases running but prevents users from adding or removing databases. 
Administrators can update from WHM or use the command documented by cPanel: 
/usr/local/cpanel/scripts/upcp --force 
CISA's August 4 enrichment recorded “Exploitation: none,” assessed the flaw as non-automatable, and rated its technical impact as total. 
That is a snapshot, and it says nothing about the days since. 
Under normal operation, cPanel supports database-level privileges that do not require SUPER access or allow global modifications. 
CVE-2026-58048 bypasses those limits by causing SQL to run in the database administrative context. 
The failure sits in cPanel's database-renaming process. 
The HackerOne CNA record says SQL mode is not preserved when a database is renamed, causing SQL to execute in root context. 
According to the company's database documentation, the system creates a replacement database, moves the original data, recreates grants and stored code, and then removes the old database and its grants. 
The vendor advisory titles the issue a privilege escalation and does not use the words SQL injection. 
The CNA classifies the same defect as CWE-89, SQL injection. 
The two records describe one bug from different angles. 
The advisory and CVE record do not identify the injected input, the affected SQL mode or the exact payload. 
Nor does it say whether Team User sub-accounts, the role-limited logins an account owner can create, meet its description of an authenticated account holder if they hold database access. 
A Critical rating is a severity measure. 
It does not say how many servers have somebody in a position to use the flaw, and here that population is set by who holds accounts on the box: a server whose accounts all belong to one company is a different proposition from one selling accounts to strangers. 
The line is not clean, since accounts can be phished or resold. 
And it narrows nothing about consequence, which CISA rated total. 
Two more in the same build 
CVE-2026-58047 (CVSS 4.0 score: 5.6) is an HTTP request-smuggling issue in cpsrvd, the daemon that serves the cPanel and WHM interfaces. 
Under limited conditions, an unauthenticated remote attacker may manipulate responses delivered to other users on the same server. 
The CNA record says credentials could leak as a result. 
Where patching has to wait, the workaround is to disable backend connection reuse by setting cpsrvd_keepalives_disabled=1 in /var/cpanel/cpanel.config and restarting cpsrvd. cPanel says the workaround forces a new TCP and TLS connection for each request on ports 2083, 2087 and 2096, increasing latency and CPU use on busy servers. cPanel credits Vincent55 Yang with reporting both CVEs. 
The third cPanel advisory covers GCVE-25-2026-07-45-3 in Exim. 
A local user's .forward file can trigger unsafe string expansion in the redirect router under certain pipe-transport configurations. 
Under cPanel's default configuration, the expansion and execution occur as the cPanel user, which the company says may allow privilege escalation from Team User sub-accounts. 
Exim's advisory says exploitation requires a redirect router providing .forward handling, an accessible pipe transport, force_command enabled on that transport and execution as a privileged user. 
Exim 4.99.5 removes the vulnerable expansion. 
Exim 4.99.5 also fixes GCVE-25-2026-07-45-1, a High-severity local directory traversal through queue-name command-line arguments. 
Exim says the flaw can access files outside the spool area and be used for privilege escalation. 
cPanel's own advisories disagree on which builds carry the fix. 
The database advisory lists build 11.118.0.71 among the patched releases; the request-smuggling and Exim advisories, published in the same release, leave the 11.118 branch off their lists entirely. 
Anyone on that branch should check the installed point release against the database advisory rather than trusting the shorter lists. 
Neither Exim advisory names a researcher. 
Each credits “the unnamed and uncredited authors whose works were ingested as the training corpus.” 
Article reasoning-pattern comparisonThis article: 1.2%Swati Khandelwal: 1.8%The Hacker News: 1.6%Confirmation Bias1.2%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anchoring Bias0.0%This article: 5.8%Swati Khandelwal: 2.8%The Hacker News: 2.8%Availability Heuristic5.8%This article: 6.2%Swati Khandelwal: 1.1%The Hacker News: 1.2%Representativeness Heuristic6.2%This article: 0.0%Swati Khandelwal: 0.6%The Hacker News: 0.5%Hindsight Bias0.0%This article: 6.2%Swati Khandelwal: 1.8%The Hacker News: 2.2%Overconfidence Bias6.2%This article: 3.8%Swati Khandelwal: 1.9%The Hacker News: 2.1%Framing Effect3.8%This article: 0.0%Swati Khandelwal: 0.6%The Hacker News: 0.8%Loss Aversion0.0%This article: 2.2%Swati Khandelwal: 0.6%The Hacker News: 0.5%Status Quo Bias2.2%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.1%Optimism Bias0.0%This article: 9.7%Swati Khandelwal: 1.4%The Hacker News: 1.3%Pessimism Bias9.7%This article: 14.6%Swati Khandelwal: 4.4%The Hacker News: 5.3%Negativity Bias14.6%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.7%Self-Serving Bias0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.4%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 0.0%Swati Khandelwal: 1.2%The Hacker News: 1.3%Recency Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Primacy Effect0.0%This article: 3.8%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias3.8%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 12.4%Swati Khandelwal: 2.8%The Hacker News: 3.1%Appeal to Authority12.4%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.1%False Dilemma0.0%This article: 1.9%Swati Khandelwal: 0.5%The Hacker News: 0.4%Slippery Slope1.9%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Circular Reasoning0.0%This article: 6.2%Swati Khandelwal: 2.6%The Hacker News: 3.3%Hasty Generalization6.2%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Bandwagon0.0%This article: 0.0%Swati Khandelwal: 0.5%The Hacker News: 0.9%Appeal to Emotion0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.3%Begging the Question0.0%This article: 0.0%Swati Khandelwal: 1.3%The Hacker News: 1.5%Post Hoc (False Cause)0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 2.6%Swati Khandelwal: 0.6%The Hacker News: 0.5%Burden of Proof2.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.7%Anecdotal0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 0.0%Swati Khandelwal: 1.8%The Hacker News: 1.7%Ambiguity (Equivocation)0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 13.0%Swati Khandelwal: 0.8%The Hacker News: 1.2%Unattributed Quote13.0%This article: 0.0%Swati Khandelwal: 0.5%The Hacker News: 0.8%Quote-first Misdirection0.0%This article: 4.5%Swati Khandelwal: 1.7%The Hacker News: 1.7%Biased Writer Voice4.5%This article: 0.0%Swati Khandelwal: 3.6%The Hacker News: 3.2%Indoctrination0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 14.4%Swati Khandelwal: 0.5%The Hacker News: 2.6%Attempt to Sell a Product or S…14.4%

772 words analyzed.

Speakers

No attributed speakers were identified in this analysis.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.