ELEVATED 3 min read 5 Aug 2026

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-58048, cwe-89, cve-2026-69263, cve-2025-8943, cwe-306, cwe-862, cve-2023-5379, cwe-770, security-brief, thehackernews-com

Key findings
01
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
CRITICAL
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity.
02
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
CRITICAL
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) CVE coverage: CVE-2026-69263, CVE-2025-8943. (Unconfirmed, single-source.)
03
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener.
HIGH
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response.
04
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
INFO
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.
05
Massive supply-chain attack compromises 440 packages under four hours
INFO
Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. (Unconfirmed, single-source.)
06
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
INFO
A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry.

Executive assessment

Today's brief leads with New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root. All 6 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

What changed: cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

Technical evidence: CVE-2026-58048; CVSS v4.0 9.4; weakness ['CWE-89']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-58048 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html>)

Finding 02 — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)

What changed: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) CVE coverage: CVE-2026-69263, CVE-2025-8943. (Unconfirmed, single-source.)

Technical evidence: CVE-2025-8943; CVSS v3.1 9.8; weakness ['CWE-306', 'CWE-862']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-8943 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-xc48-889x-5qmw>)

Finding 03 — A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener.

What changed: A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response.

Technical evidence: CVE-2023-5379; CVSS v3.1 7.5; weakness ['CWE-770']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2023-5379 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2023-5379>)

Finding 04 — The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

What changed: Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: unit42.paloaltonetworks.com](<https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/>)

Finding 05 — Massive supply-chain attack compromises 440 packages under four hours

What changed: Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. (Unconfirmed, single-source.)

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: cyberscoop.com](<https://cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/>)

Finding 06 — Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

What changed: A credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html>)

cve-2023-5379cve-2025-8943cve-2026-58048cve-2026-69263cwe-306cwe-770cwe-862cwe-89security-briefthehackernews-com

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.