Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Critical cPanel Database Privilege Escalation Security Updates

A critical vulnerability tracked as CVE-2026-58048 has been identified in cPanel & WHM (Web Host Manager) and related services, including WP Squared (WP2). The flaw allows an authenticated local hosting customer to execute SQL commands within the database's administrative root context, effectively bypassing account privileges.

 

Affected Systems:

 
  • cPanel & WHM versions earlier than 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, and 11.136.0.32.
  • WP Squared versions earlier than 138.1.6 (WP2)
 

Security Risks

 

The successful exploitation of this vulnerability could allow attackers to bypass authentication controls and gain unauthorized administrative access to cPanel and WHM systems without valid credentials.

 

For more information on this vulnerability and related updates, please refer to cPanel security advisory for CVE-2026-58048

 

Recommended Actions

 

The National Cyber Security Authority (NCSA) recommends users and system administrators:

  • Upgrade cPanel and WHM to the latest supported versions to ensure continued access to security updates and technical support.
  • If patching cannot be applied immediately, restrict MySQL access for cPanel users as a temporary control.
  • Ensure valid backups are available before applying updates.
 

For further information and support, please contact the National Cyber Security Authority (NCSA) by emailto rwcsirt@ncsa.gov.rw or call us on 9009.

 

References

06 August 2026

© 2026 National Cyber Security Authority