Alert: Critical cPanel Database Privilege Escalation Security Updates
A critical vulnerability tracked as CVE-2026-58048 has been identified in cPanel & WHM (Web Host Manager) and related services, including WP Squared (WP2). The flaw allows an authenticated local hosting customer to execute SQL commands within the database's administrative root context, effectively bypassing account privileges.
Affected Systems:
Security Risks
The successful exploitation of this vulnerability could allow attackers to bypass authentication controls and gain unauthorized administrative access to cPanel and WHM systems without valid credentials.
For more information on this vulnerability and related updates, please refer to cPanel security advisory for CVE-2026-58048
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators:
For further information and support, please contact the National Cyber Security Authority (NCSA) by emailto rwcsirt@ncsa.gov.rw or call us on 9009.
References
06 August 2026
More updates
© 2026 National Cyber Security Authority