hacker-news · Crawled Aug 4, 2026

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Read original article ↗

AI Summary

cPanel has patched a critical vulnerability, CVE-2026-58048 (CVSS 4.0: 9.4), that allows an authenticated hosting customer to execute SQL commands with full administrative database privileges, effectively crossing the privilege boundary into the server's root database context. The flaw resides in the database-renaming process, where SQL mode is not preserved, leading to execution in root context. This could lead to full operating system compromise depending on configuration. Two additional vulnerabilities were patched in the same release: CVE-2026-58047, an HTTP request-smuggling issue in cpsrvd, and a local privilege escalation in Exim via unsafe string expansion in .forward files.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.