Specifically, it let an ordinary, authenticated account run SQL commands with full administrative database privileges. CVE-2026-58048 carries a CVSS 4.0 score of 9.4, and it touches every supported version of cPanel & WHM plus WP Squared. To exploit it, an attacker only needs a valid cPanel account with access to the MySQL or MariaDB feature, and plenty of regular customers already have that. From there, cPanel says the account holder could run arbitrary database commands as if they held root access. For anyone who can’t update immediately, revoking the MySQL feature from cPanel users works as a stopgap.