Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026080605081818 | Publication Time | 2026-08-06 17:34:19 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-06 17:34:19 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】cPanel and WHM (WebHost Manager) Contain a Critical Cybersecurity Vulnerability (CVE-2026-58048) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000007 Recently, cPanel issued a critical cybersecurity advisory (CVE-2026-58048, CVSS 4.x: 9.4). This vulnerability exists in the cPanel and WHM (WebHost Manager) management systems and is classified as a privilege escalation vulnerability. An authenticated cPanel account with access privileges to a MySQL/MariaDB database may exploit this vulnerability to obtain full administrative privileges to execute arbitrary database commands. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
All versions of cPanel and WHM (WebHost Manager) |
|||
|
[Recommended Actions] Please update to the following versions: cPanel/WHM version 11.110.0.137, cPanel/WHM version 11.118.0.71, cPanel/WHM version 11.126.0.78, cPanel/WHM version 11.134.0.48, cPanel/WHM version 11.136.0.32, cPanel/WHM version 138.1.6 (WP2) |
|||
|
[Reference] 1. https://support.cpanel.net/hc/en-us/articles/42285745783703-Security-CVE-2026-58048-Database-Privilege-Escalation |
|||