DIRAS TAKE
Urgent: public exploit code exists and vendor updates are available; apply the vendor fixes listed below promptly or restrict access to the cPanel management interfaces until you can patch.
What is CVE-2026-58048?
A low-privilege user can execute SQL in the root database context on cPanel, allowing elevated database access and potential data modification; this is tracked as CVE-2026-58048. The flaw is an SQL injection (CWE-89) that affects cPanel 11.x releases before the fixed builds listed below; an attacker needs a valid low-privileged account on the target cPanel instance and web access to trigger the issue. Multiple 11.x branches are fixed in specific builds named by the vendor. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Which versions of WebPros cPanel are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| cPanel 11.x | before 11.110.0.137 | 11.110.0.137 |
| cPanel 11.x | before 11.126.0.78 | 11.126.0.78 |
| cPanel 11.x | before 11.134.0.48 | 11.134.0.48 |
| cPanel 11.x | before 11.136.0.32 | 11.136.0.32 |
| cPanel 11.x | before 11.137.9999.99 | 11.137.9999.99 |
| cPanel 11.x | before 11.118.0.71 | 11.118.0.71 |
| WP Squared 11.x | before 11.138.1.6 | 11.138.1.6 |
Is CVE-2026-58048 being exploited?
Public exploit code is available.
How to fix CVE-2026-58048
- Upgrade cPanel 11.x to one of the fixed builds: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, 11.137.9999.99, or WP Squared 11.x to 11.138.1.6.
- If you cannot patch immediately, restrict access to cPanel management ports and web panels to trusted IPs and internal networks.
- Review cPanel and database logs for suspicious database rename or SQL activity and investigate any anomalies.
- Follow vendor guidance and deploy configuration hardening recommended by WebPros for cPanel.
Frequently asked questions
Is CVE-2026-58048 being actively exploited?
Public exploit code is available for CVE-2026-58048; there is at least public proof-of-concept code.
Which cPanel versions are affected by CVE-2026-58048?
Multiple cPanel 11.x branches are affected; any release before the fixed builds listed by the vendor is vulnerable (see fixed builds such as 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, 11.137.9999.99, and WP Squared 11.x 11.138.1.6).
Is there a patch for CVE-2026-58048?
Yes. WebPros published fixes; update to the specified fixed builds for the affected cPanel 11.x branches or WP Squared 11.x 11.138.1.6.
Does CVE-2026-58048 require authentication?
Yes. The issue requires a valid low-privileged account on the cPanel instance to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-58048
- cve.org/CVERecord?id=CVE-2026-58048
- support.cpanel.net/hc/en-us/articles/42285745783703-CVE-2026-58048-Database-Privilege-Escalation
- docs.cpanel.net/changelogs/138-change-log
- All WebPros CVEs on CVE Radar
- CVEs published in September 2026