Skip to content
July 30 advisory

July 30 advisory

support.cpanel.net September 9, 2026

A privilege escalation vulnerability exists in cPanel & WHM's database management functionality.

Affected Product Versions

An authenticated cPanel account holder with access to the MySQL/MariaDB database feature could potentially execute arbitrary database commands with full administrative privileges. Depending on the operating system and database engine configuration, this may extend to operating-system-level compromise.

Update to the latest patched version: How do I update cPanel/WHM?

Servers that cannot immediately upgrade can temporarily revoke the "MySQL" feature from cPanel users. This will not disable existing databases but just prevent adding/removing. To do so, you can follow the steps here: How to edit a feature list

WebPros thanks Vincent55 Yang for responsibly disclosing this issue.

Extracted Entities