Date Posted: 2026/08/07
【Vulnerability Alert】Critical Security Vulnerability in cPanel and WHM (WebHost Manager) (CVE-2026-58048)
- Subject: 【Vulnerability Alert】Critical Security Vulnerability in cPanel and WHM (WebHost Manager) (CVE-2026-58048)
- Description:
- Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) TWCERTCC-200-202608-00000007
- Recently, cPanel released a critical security advisory (CVE-2026-58048, CVSS 4.x: 9.4). This vulnerability exists in the cPanel and WHM (WebHost Manager) management systems and is classified as a privilege escalation vulnerability. An authenticated cPanel account with access permissions to MySQL/MariaDB databases could exploit this vulnerability to execute arbitrary database commands with full administrative privileges.
- Affected Platforms:
- All versions of cPanel and WHM (WebHost Manager)
- Recommendations:
- Please update to the following versions or later: cPanel/WHM version 11.110.0.137, cPanel/WHM version 11.118.0.71, cPanel/WHM version 11.126.0.78, cPanel/WHM version 11.134.0.48, cPanel/WHM version 11.136.0.32, cPanel/WHM version 138.1.6 (WP2)
- Reference Information:
Computer and Communication Center
Network Systems Division