PT-2026-66785 · Cpanel · Cpanel

·

CVE-2026-58048

·

Published

2026-07-31

·

Updated

2026-09-11

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions cPanel (affected versions not specified)
Description Improper preservation of SQL mode when renaming databases allows the execution of SQL commands in root context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58048

Affected Products

Cpanel