Date Posted: 2026/08/07

【Vulnerability Alert】Critical Security Vulnerability in cPanel and WHM (WebHost Manager) (CVE-2026-58048)

  • Subject: 【Vulnerability Alert】Critical Security Vulnerability in cPanel and WHM (WebHost Manager) (CVE-2026-58048)


  • Description:
    • Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) TWCERTCC-200-202608-00000007
    • Recently, cPanel released a critical security advisory (CVE-2026-58048, CVSS 4.x: 9.4). This vulnerability exists in the cPanel and WHM (WebHost Manager) management systems and is classified as a privilege escalation vulnerability. An authenticated cPanel account with access permissions to MySQL/MariaDB databases could exploit this vulnerability to execute arbitrary database commands with full administrative privileges.
  • Affected Platforms:
    • All versions of cPanel and WHM (WebHost Manager)
  • Recommendations:
    • Please update to the following versions or later: cPanel/WHM version 11.110.0.137, cPanel/WHM version 11.118.0.71, cPanel/WHM version 11.126.0.78, cPanel/WHM version 11.134.0.48, cPanel/WHM version 11.136.0.32, cPanel/WHM version 138.1.6 (WP2)
  • Reference Information:

Computer and Communication Center
Network Systems Division