Back to Blog

Emerging Threat: (CVE-2026-58048) cPanel & WHM Database Privilege Escalation via Database Rename

Sample of assets impacted by cPanel DB Privilege Escalation, identified by the CyCognito platform

What is CVE-2026-58048?

CVE-2026-58048 is a privilege escalation vulnerability in the database management functionality of cPanel & WHM, the hosting control panel developed by WebPros. An authenticated cPanel account holder with access to the MySQL/MariaDB database feature can execute arbitrary database commands with full administrative privileges, rather than being confined to the databases and grants tied to their own account.

The CVE record carries a CVSS v4.0 base score of 9.4 (Critical). The record was assigned through HackerOne as the CNA and classifies the defect as SQL injection, while the vendor advisory describes it as privilege escalation. Both descriptions refer to the same underlying flaw.

Exploitation is post-authentication. An attacker needs a valid cPanel account and the database feature enabled on it, which is the default posture for ordinary customer accounts on most shared and reseller hosting platforms. That precondition is low: on multi-tenant infrastructure, an account can be bought, and any single compromised customer account is enough.

The impact does not necessarily stop at the database. The vendor states that depending on the operating system and database engine configuration, the flaw may extend to operating-system-level compromise. CISA’s enrichment of the CVE record on July 31, 2026 recorded exploitation as none, assessed the flaw as not automatable, and rated technical impact as total.

Public proof-of-concept code has since been published. The vendor advisory and the CVE record do not identify the injected input or the exact payload, though third-party analyses attribute the flaw to the database rename operation, where SQL is reported to execute in the database administrative context rather than the calling account’s context.

What assets are affected by CVE-2026-58048?

All supported versions of cPanel & WHM are affected, along with WP Squared. This is not a narrow version band. Any cPanel or WHM installation that has not been moved to one of the patched builds should be treated as affected.

In practice, an affected asset is a hosting control panel exposed to the internet. cPanel and WHM run their own web services on dedicated ports rather than behind the main site, so they typically appear in an external attack surface as hostnames or IP addresses answering on TCP/2082 and TCP/2083 for cPanel, TCP/2086 and TCP/2087 for WHM, and TCP/2095 and TCP/2096 for webmail. Many are reachable directly by IP address on shared hosting infrastructure, alongside a cpanel. or whm. hostname pointed at the same server. The vulnerable condition requires the MySQL/MariaDB feature to be present in the feature list applied to customer accounts, which is the standard configuration.

These assets tend to be internet-facing by design. A control panel exists so that customers, agencies, and resellers can log in from anywhere and manage their own sites, which means restricting it to a corporate network defeats its purpose. They also tend to be overlooked, because the organization whose brand is on the website is often not the party running the server. Marketing microsites, regional brand sites, campaign pages, and sites inherited through acquisition frequently sit on shared cPanel hosting arranged by an agency or a local team, outside the central asset inventory and outside the patching cycle that covers the rest of the estate.

What does our data show about exposure patterns?

Exposure in this set is led by Industrials at 22.3% of observed assets, with Consumer Discretionary contributing 18.8%. Communication Services accounts for a further 9.1%. The Others bucket is unusually large at 49.8%, made up of unclassified organizations and a long tail of smaller sectors, none of which reaches double digits on its own.

Industrials and Consumer Discretionary share a structural trait that produces this kind of exposure: both operate large numbers of small web properties that are not managed by the same team that manages core infrastructure.

Manufacturers, distributors, and logistics operators maintain regional sites, dealer and partner portals, and product microsites, often commissioned locally and hosted wherever the local agency hosts things. Retail, hospitality, and consumer brands add campaign sites and franchise pages with short intended lifespans and long actual ones. Shared cPanel hosting is the natural home for all of it, and the account that holds the panel login is rarely the security team.

The flatness of the distribution is the more useful signal. With roughly half of observed assets falling outside the top three sectors, the pattern does not point to a sector-specific technology choice. It points to an ownership gap. cPanel is seldom a deliberate enterprise procurement decision. It arrives with a hosting relationship someone else set up, and it keeps running long after the project that justified it ended. That is what makes a post-authentication flaw on a shared server a meaningful external risk: the organization that carries the consequence often does not know the panel is there, and does not control who else holds an account on the same box.

Are fixes available?

Patches are available. WebPros published its advisory on July 30, 2026 with fixed builds across every supported cPanel & WHM branch: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, and 11.136.0.32, plus 138.1.6 for WP Squared. The same release also addresses CVE-2026-58047, an HTTP request smuggling issue in the cpsrvd daemon, and an Exim privilege escalation issue.

The correct build depends on the deployment branch, so there is no single target version. Administrators should confirm which branch each server tracks before updating, and apply the update through WHM or the vendor’s documented upgrade path. Servers on older or long-term support branches need the matching build from the list above rather than the newest release.

Organizations that do not run their own cPanel servers still carry the exposure. Where sites are hosted by an agency, reseller, or hosting provider, patching is the provider’s action and verification is the customer’s. Defenders should confirm the patched build directly with whoever operates the server rather than assuming the update has been applied.

Until patching is confirmed, defenders should:

  • Inventory internet-facing cPanel and WHM interfaces across all hosting providers and agencies
  • Revoke the MySQL feature from cPanel feature lists as a temporary containment measure
  • Restrict WHM interface access to known administrative source addresses
  • Monitor MySQL and MariaDB logs for unexpected database rename operations
  • Audit database grants for accounts holding unexpected administrative privileges
  • Review customer and reseller accounts provisioned on shared servers before the patch date

How can CyCognito help your organization?

CyCognito published an Emerging Threat Advisory for CVE-2026-58048 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.

To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.


Request a free scan

See Exactly What Attackers See

Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally .

Request a Scan
Top Attack Paths