Affected Systems
cPanel & WHM all supported versions prior to 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and WP Squared prior to 138.1.6. Requires authenticated cPanel account with MySQL/MariaDB feature access.
Exploitation Status
No active exploitation reported as of August 4, 2026 per CISA enrichment. CISA assessed the flaw as non-automatable. No public PoC identified in reporting.
Business Impact
Authenticated hosting customers can execute arbitrary SQL commands with full database administrative privileges, bypassing account isolation. CISA rates technical impact as total. Depending on database engine and OS configuration, exploitation may extend to operating-system-level compromise. Risk is highest on shared hosting environments where multiple untrusted customers hold accounts on the same server. Single-tenant environments face lower risk but still allow privilege escalation from compromised or malicious accounts.
Urgency
🟠Within 24 hours
Recommended Actions
- Update cPanel & WHM to patched versions: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32 or later using /usr/local/cpanel/scripts/upcp --force
- Update WP Squared to version 138.1.6 or later
- If immediate patching is not possible, temporarily revoke the MySQL feature from cPanel users via WHM to prevent database creation/deletion while leaving existing databases operational
- Review database audit logs for unexpected administrative-level SQL commands executed by non-administrative cPanel accounts since deployment
- Prioritize patching on multi-tenant shared hosting servers where multiple customer accounts exist on the same infrastructure
