CVE-2026-58048

Summary

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Affected Software

VendorProductVersion RangeStatus
WebProscPanel11.110.0.137 < 11.110.0.137affected
WebProscPanel11.126.0.78 < 11.126.0.78affected
WebProscPanel11.134.0.48 < 11.134.0.48affected
WebProscPanel11.136.0.32 < 11.136.0.32affected
WebProscPanel11.137.9999.99 < 11.137.9999.99affected
WebProscPanel11.118.0.71 < 11.118.0.71affected
WebProsWP Squared11.138.1.6 < 11.138.1.6affected

Weaknesses

  • CWE-89: CWE-89 SQL Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References