A privilege escalation vulnerability exists in cPanel & WHM's database management functionality.
Affected Product Versions
An authenticated cPanel account holder with access to the MySQL/MariaDB database feature could potentially execute arbitrary database commands with full administrative privileges. Depending on the operating system and database engine configuration, this may extend to operating-system-level compromise.
Update to the latest patched version: How do I update cPanel/WHM?
Servers that cannot immediately upgrade can temporarily revoke the "MySQL" feature from cPanel users. This will not disable existing databases but just prevent adding/removing. To do so, you can follow the steps here: How to edit a feature list
WebPros thanks Vincent55 Yang for responsibly disclosing this issue.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
