Security Updates for cPanel and WP Squared
WebPros has issued a security advisory addressing HTTP request smuggling and database privilege escalation vulnerabilities in cPanel and WP Squared products.
WebPros has released a security advisory (AV26-772) addressing multiple vulnerabilities affecting their cPanel and WP Squared product lines. These vulnerabilities include CVE-2026-58047, which relates to HTTP Request Smuggling, and CVE-2026-58048, which involves database privilege escalation.
The scope of the affected versions is extensive, covering multiple release branches of cPanel (11.110, 11.118, 11.126, 11.134, 11.136, and 138.1) and WP Squared versions prior to 11.138.1.6. These flaws pose significant risks to web hosting environments, as HTTP request smuggling can potentially lead to cache poisoning or bypassing security controls, while the privilege escalation vulnerability could allow an authenticated user to gain unauthorized access to database administrative functions. Administrators are urged to apply the identified patches to maintain the security and integrity of their hosting platforms.
Impact
Successful exploitation of these vulnerabilities could result in unauthorized administrative access to databases or the manipulation of web server traffic. Given the ubiquitous nature of cPanel in the web hosting industry, these vulnerabilities potentially impact thousands of hosting providers and the underlying websites they manage, leading to data exfiltration or site defacement.
Recommendation
Prioritized, concrete actions for detection engineering and administrative teams:
- Immediately patch all instances of cPanel and WP Squared to the versions specified in the WebPros security advisory (AV26-772).
- Verify patch levels for all identified affected product versions listed in the vendor advisory.
- Review web server access logs for anomalous HTTP request patterns that deviate from standard traffic profiles, specifically targeting headers associated with HTTP Request Smuggling (e.g., conflicting Content-Length and Transfer-Encoding headers).
Immediate actions
Patch cPanel and WP Squared to the latest versions defined in AV26-772.