• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-58048: authenticated sql injection in WebPros cPanel

A low-privilege user can execute SQL in the root database context on cPanel, allowing elevated database access and potential data modification; this is tracked as CVE-2026-58048. The flaw is an SQL injection (CWE-89) that affects cPanel 11.x releases before the fixed builds listed below; an attacker needs a valid low-privileged account on the target cPanel instance and web access to trigger the issue. Multiple 11.x branches are fixed in specific builds named by the vendor.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 4.0
9.4CRITICAL
EPSS
0.00561
CWE
CWE-89
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists and vendor updates are available; apply the vendor fixes listed below promptly or restrict access to the cPanel management interfaces until you can patch.

What is CVE-2026-58048?

A low-privilege user can execute SQL in the root database context on cPanel, allowing elevated database access and potential data modification; this is tracked as CVE-2026-58048. The flaw is an SQL injection (CWE-89) that affects cPanel 11.x releases before the fixed builds listed below; an attacker needs a valid low-privileged account on the target cPanel instance and web access to trigger the issue. Multiple 11.x branches are fixed in specific builds named by the vendor. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of WebPros cPanel are affected?

BRANCHAFFECTEDFIXED
cPanel 11.xbefore 11.110.0.13711.110.0.137
cPanel 11.xbefore 11.126.0.7811.126.0.78
cPanel 11.xbefore 11.134.0.4811.134.0.48
cPanel 11.xbefore 11.136.0.3211.136.0.32
cPanel 11.xbefore 11.137.9999.9911.137.9999.99
cPanel 11.xbefore 11.118.0.7111.118.0.71
WP Squared 11.xbefore 11.138.1.611.138.1.6

Is CVE-2026-58048 being exploited?

Public exploit code is available.

How to fix CVE-2026-58048

  1. Upgrade cPanel 11.x to one of the fixed builds: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, 11.137.9999.99, or WP Squared 11.x to 11.138.1.6.
  2. If you cannot patch immediately, restrict access to cPanel management ports and web panels to trusted IPs and internal networks.
  3. Review cPanel and database logs for suspicious database rename or SQL activity and investigate any anomalies.
  4. Follow vendor guidance and deploy configuration hardening recommended by WebPros for cPanel.

Frequently asked questions

Is CVE-2026-58048 being actively exploited?

Public exploit code is available for CVE-2026-58048; there is at least public proof-of-concept code.

Which cPanel versions are affected by CVE-2026-58048?

Multiple cPanel 11.x branches are affected; any release before the fixed builds listed by the vendor is vulnerable (see fixed builds such as 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, 11.137.9999.99, and WP Squared 11.x 11.138.1.6).

Is there a patch for CVE-2026-58048?

Yes. WebPros published fixes; update to the specified fixed builds for the affected cPanel 11.x branches or WP Squared 11.x 11.138.1.6.

Does CVE-2026-58048 require authentication?

Yes. The issue requires a valid low-privileged account on the cPanel instance to exploit.

References