phpMyAdmin access denied for cPanel user — malformed password hash on MySQL 8.0.46
Note: this resembles the pattern described in the old CPANEL-25785 thread (system-user MySQL password being regenerated/reset automatically during internal cPanel operations), though that specific bug was resolved in v78. This appears to be a related but distinct issue on 134.0.21 with MySQL 8.0.46 / caching_sha2_password.
Server: cPanel 134.0.21, MySQL 8.0.46, unmanaged VPS (no host support available)
Affected account: jeepcj
phpMyAdmin fails to load for this account with:
mysqli_sql_exception: Access denied for user 'jeepcj'@'localhost' (using password: YES)
This began after a database copy operation in phpMyAdmin started hanging indefinitely (previously completed in seconds). Checking /usr/local/cpanel/logs/error_log at the time showed cPanel's automatic privilege-refresh step failing on every database create/copy operation with:
Cpanel::Exception::Database::Error: The system received an error from the "MySQL" database "mysql": 1827 (The password hash doesn't have the expected format.)
The failing query was:
ALTER USER IF EXISTS 'jeepcj'@'localhost' IDENTIFIED WITH 'caching_sha2_password' AS '...'
The hash value cPanel generated and attempted to write appeared truncated.
Troubleshooting so far:
- Used WHM's "Change Database User Password" tool to reset this user's password. It reported success, but did not resolve the phpMyAdmin login, and in one case did not actually recreate the user row in mysql.user at all despite the success message.
- Manually dropped and recreated jeepcj@localhost directly in MySQL using mysql_native_password. Confirmed via direct command-line login (mysql -u jeepcj -p... -h localhost) that the account and password work correctly outside of cPanel.
- phpMyAdmin still fails to authenticate afterward with the same access denied error.
- Monitored /usr/local/cpanel/logs/error_log in real time while reproducing the phpMyAdmin failure — nothing is logged there when it fails, so the failure appears to originate in phpMyAdmin's single-sign-on session handling rather than a step visible in standard cPanel logs.
- The other three host entries for this same MySQL user (remote IPs) are unaffected and use mysql_native_password without issue.
Since the underlying MySQL credential is confirmed working and the failure is isolated to cPanel's phpMyAdmin SSO flow for this one account, could you advise what's causing this and how to restore phpMyAdmin access?
-
Hey there! I'm doing some testing on this one and I'll post as soon as I know more!
0 -
I'm not able to reproduce this on a test machine at this point. Are you able to create a ticket so we can check this directly on the server?
0 -
Thank you for looking into it. After a nine hour session with Gemini everything is now working.
0 -
Ooof, that sounds rough. Were you able to determine what the exact issue was?
0 -
Sorry, not really. I know that the cpanel DB had to be rebuilt many times and users had to be readded. Great thing the issue never actually killed any of my sites. After so many things that were tried I am not actually sure what actually fixed it.
0
Please sign in to leave a comment.
Comments
5 comments