Description:
Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) TWCERTCC-200-202608-00000007
Recently, cPanel released a critical security advisory (CVE-2026-58048, CVSS 4.x: 9.4). This vulnerability exists in the cPanel and WHM (WebHost Manager) management systems and is classified as a privilege escalation vulnerability. An authenticated cPanel account with access permissions to MySQL/MariaDB databases could exploit this vulnerability to execute arbitrary database commands with full administrative privileges.
Affected Platforms:
Recommendations:
Please update to the following versions or later: cPanel/WHM version 11.110.0.137, cPanel/WHM version 11.118.0.71, cPanel/WHM version 11.126.0.78, cPanel/WHM version 11.134.0.48, cPanel/WHM version 11.136.0.32, cPanel/WHM version 138.1.6 (WP2)
Reference Information:
-
-
Computer and Communication Center
Network Systems Division