CRITICAL: cPanel Flaw Lets Hosting Customers Run SQL as Database Root
cPanel and WHM patched CVE-2026-58048, a CVSS 9.4 critical flaw that lets any authenticated hosting customer with database access execute SQL in the database root context. Shared hosting servers carry the real exposure, since the only prerequisite is a paying account. Patched builds are out across every supported release tier.