CVE-2026-58048: WebPros cPanel
Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
Affected products
- WebPros cPanel: before 11.110.0.137 (fixed in 11.110.0.137); before 11.126.0.78 (fixed in 11.126.0.78); before 11.134.0.48 (fixed in 11.134.0.48); before 11.136.0.32 (fixed in 11.136.0.32); before 11.137.9999.99 (fixed in 11.137.9999.99); before 11.118.0.71 (fixed in 11.118.0.71)
- WebPros Wp Squared: before 11.138.1.6 (fixed in 11.138.1.6)
Published 2026-07-31. Last modified 2026-09-03.