{"id":2781,"date":"2026-08-09T09:29:07","date_gmt":"2026-08-09T16:29:07","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=2781"},"modified":"2026-08-09T09:32:01","modified_gmt":"2026-08-09T16:32:01","slug":"emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/","title":{"rendered":"Emerging Threat: (CVE-2026-58048) cPanel &#038; WHM Database Privilege Escalation via Database Rename"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1280\" height=\"655\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1280x655.png\" alt=\"\" class=\"wp-image-2787\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1280x655.png 1280w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-512x262.png 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-768x393.png 768w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1536x786.png 1536w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png 1982w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><figcaption class=\"wp-element-caption\"><em>Sample of assets impacted by cPanel DB Privilege Escalation, identified by the CyCognito platform<\/em><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What is CVE-2026-58048?<\/h2>\n\n\n\n<p>CVE-2026-58048 is a privilege escalation vulnerability in the database management functionality of cPanel &amp; WHM, the hosting control panel developed by WebPros. An authenticated cPanel account holder with access to the MySQL\/MariaDB database feature can execute arbitrary database commands with full administrative privileges, rather than being confined to the databases and grants tied to their own account.<\/p>\n\n\n\n<p>The CVE record carries a CVSS v4.0 base score of 9.4 (Critical). The record was assigned through HackerOne as the CNA and classifies the defect as SQL injection, while the vendor advisory describes it as privilege escalation. Both descriptions refer to the same underlying flaw.<\/p>\n\n\n\n<p>Exploitation is post-authentication. An attacker needs a valid cPanel account and the database feature enabled on it, which is the default posture for ordinary customer accounts on most shared and reseller hosting platforms. That precondition is low: on multi-tenant infrastructure, an account can be bought, and any single compromised customer account is enough.<\/p>\n\n\n\n<p>The impact does not necessarily stop at the database. The vendor states that depending on the operating system and database engine configuration, the flaw may extend to operating-system-level compromise. CISA&#8217;s enrichment of the CVE record on July 31, 2026 recorded exploitation as none, assessed the flaw as not automatable, and rated technical impact as total. <\/p>\n\n\n\n<p>Public proof-of-concept code has since been published. The vendor advisory and the CVE record do not identify the injected input or the exact payload, though third-party analyses attribute the flaw to the database rename operation, where SQL is reported to execute in the database administrative context rather than the calling account&#8217;s context.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What assets are affected by CVE-2026-58048?<\/h2>\n\n\n\n<p>All supported versions of cPanel &amp; WHM are affected, along with WP Squared. This is not a narrow version band. Any cPanel or WHM installation that has not been moved to one of the patched builds should be treated as affected.<\/p>\n\n\n\n<p>In practice, an affected asset is a hosting control panel exposed to the internet. cPanel and WHM run their own web services on dedicated ports rather than behind the main site, so they typically appear in an external attack surface as hostnames or IP addresses answering on <code>TCP\/2082<\/code> and <code>TCP\/2083<\/code> for cPanel, <code>TCP\/2086<\/code> and <code>TCP\/2087<\/code> for WHM, and <code>TCP\/2095<\/code> and <code>TCP\/2096<\/code> for webmail. Many are reachable directly by IP address on shared hosting infrastructure, alongside a <code>cpanel.<\/code> or <code>whm.<\/code> hostname pointed at the same server. The vulnerable condition requires the MySQL\/MariaDB feature to be present in the feature list applied to customer accounts, which is the standard configuration.<\/p>\n\n\n\n<p>These assets tend to be internet-facing by design. A control panel exists so that customers, agencies, and resellers can log in from anywhere and manage their own sites, which means restricting it to a corporate network defeats its purpose. They also tend to be overlooked, because the organization whose brand is on the website is often not the party running the server. Marketing microsites, regional brand sites, campaign pages, and sites inherited through acquisition frequently sit on shared cPanel hosting arranged by an agency or a local team, outside the central asset inventory and outside the patching cycle that covers the rest of the estate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does our data show about exposure patterns?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"750\" src=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-238.png\" alt=\"\" class=\"wp-image-2782\" srcset=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-238.png 1200w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-238-512x320.png 512w, https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-238-768x480.png 768w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<p>Exposure in this set is led by Industrials at 22.3% of observed assets, with Consumer Discretionary contributing 18.8%. Communication Services accounts for a further 9.1%. The Others bucket is unusually large at 49.8%, made up of unclassified organizations and a long tail of smaller sectors, none of which reaches double digits on its own.<\/p>\n\n\n\n<p>Industrials and Consumer Discretionary share a structural trait that produces this kind of exposure: both operate large numbers of small web properties that are not managed by the same team that manages core infrastructure. <\/p>\n\n\n\n<p>Manufacturers, distributors, and logistics operators maintain regional sites, dealer and partner portals, and product microsites, often commissioned locally and hosted wherever the local agency hosts things. Retail, hospitality, and consumer brands add campaign sites and franchise pages with short intended lifespans and long actual ones. Shared cPanel hosting is the natural home for all of it, and the account that holds the panel login is rarely the security team.<\/p>\n\n\n\n<p>The flatness of the distribution is the more useful signal. With roughly half of observed assets falling outside the top three sectors, the pattern does not point to a sector-specific technology choice. It points to an ownership gap. cPanel is seldom a deliberate enterprise procurement decision. It arrives with a hosting relationship someone else set up, and it keeps running long after the project that justified it ended. That is what makes a post-authentication flaw on a shared server a meaningful external risk: the organization that carries the consequence often does not know the panel is there, and does not control who else holds an account on the same box.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are fixes available?<\/h2>\n\n\n\n<p>Patches are available. WebPros published its advisory on July 30, 2026 with fixed builds across every supported cPanel &amp; WHM branch: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, and 11.136.0.32, plus 138.1.6 for WP Squared. The same release also addresses CVE-2026-58047, an HTTP request smuggling issue in the <code>cpsrvd<\/code> daemon, and an Exim privilege escalation issue.<\/p>\n\n\n\n<p>The correct build depends on the deployment branch, so there is no single target version. Administrators should confirm which branch each server tracks before updating, and apply the update through WHM or the vendor&#8217;s documented upgrade path. Servers on older or long-term support branches need the matching build from the list above rather than the newest release.<\/p>\n\n\n\n<p>Organizations that do not run their own cPanel servers still carry the exposure. Where sites are hosted by an agency, reseller, or hosting provider, patching is the provider&#8217;s action and verification is the customer&#8217;s. Defenders should confirm the patched build directly with whoever operates the server rather than assuming the update has been applied.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are there any other recommended actions to take?<\/h2>\n\n\n\n<p>Until patching is confirmed, defenders should:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inventory internet-facing cPanel and WHM interfaces across all hosting providers and agencies<\/li>\n\n\n\n<li>Revoke the <code>MySQL<\/code> feature from cPanel feature lists as a temporary containment measure<\/li>\n\n\n\n<li>Restrict WHM interface access to known administrative source addresses<\/li>\n\n\n\n<li>Monitor MySQL and MariaDB logs for unexpected database rename operations<\/li>\n\n\n\n<li>Audit database grants for accounts holding unexpected administrative privileges<\/li>\n\n\n\n<li>Review customer and reseller accounts provisioned on shared servers before the patch date<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How can CyCognito help your organization?<\/h2>\n\n\n\n<p>CyCognito published an Emerging Threat Advisory for CVE-2026-58048 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.<\/p>\n\n\n\n<p>To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, <a href=\"https:\/\/www.cycognito.com\/demo\/\">contact us to request a demo<\/a>.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A privilege escalation flaw in cPanel &#038; WHM&#8217;s database management lets any authenticated hosting account execute database commands with full administrative privileges, exposing every database on the server.<\/p>\n","protected":false},"author":39,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[250],"tags":[],"class_list":["post-2781","post","type-post","status-publish","format-standard","hentry","category-emerging-threats"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Emerging Threat: (CVE-2026-58048) cPanel &amp; WHM Database Privilege Escalation via Database Rename | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Emerging Threat: (CVE-2026-58048) cPanel &amp; WHM Database Privilege Escalation via Database Rename | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"A privilege escalation flaw in cPanel &amp; WHM&#039;s database management lets any authenticated hosting account execute database commands with full administrative privileges, exposing every database on the server.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-09T16:29:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-09T16:32:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1982\" \/>\n\t<meta property=\"og:image:height\" content=\"1014\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Igal Zeifman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Igal Zeifman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\"},\"author\":{\"name\":\"Igal Zeifman\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\"},\"headline\":\"Emerging Threat: (CVE-2026-58048) cPanel &#038; WHM Database Privilege Escalation via Database Rename\",\"datePublished\":\"2026-08-09T16:29:07+00:00\",\"dateModified\":\"2026-08-09T16:32:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\"},\"wordCount\":1111,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1280x655.png\",\"articleSection\":[\"Emerging Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\",\"name\":\"Emerging Threat: (CVE-2026-58048) cPanel & WHM Database Privilege Escalation via Database Rename | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1280x655.png\",\"datePublished\":\"2026-08-09T16:29:07+00:00\",\"dateModified\":\"2026-08-09T16:32:01+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png\",\"width\":1982,\"height\":1014},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Emerging Threat: (CVE-2026-58048) cPanel &#038; WHM Database Privilege Escalation via Database Rename\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\",\"name\":\"Igal Zeifman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"caption\":\"Igal Zeifman\"},\"description\":\"VP of Marketing\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Emerging Threat: (CVE-2026-58048) cPanel & WHM Database Privilege Escalation via Database Rename | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/","og_locale":"en_US","og_type":"article","og_title":"Emerging Threat: (CVE-2026-58048) cPanel & WHM Database Privilege Escalation via Database Rename | CyCognito Blog","og_description":"A privilege escalation flaw in cPanel & WHM's database management lets any authenticated hosting account execute database commands with full administrative privileges, exposing every database on the server.","og_url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/","og_site_name":"CyCognito Blog","article_published_time":"2026-08-09T16:29:07+00:00","article_modified_time":"2026-08-09T16:32:01+00:00","og_image":[{"width":1982,"height":1014,"url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png","type":"image\/png"}],"author":"Igal Zeifman","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Igal Zeifman","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/"},"author":{"name":"Igal Zeifman","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3"},"headline":"Emerging Threat: (CVE-2026-58048) cPanel &#038; WHM Database Privilege Escalation via Database Rename","datePublished":"2026-08-09T16:29:07+00:00","dateModified":"2026-08-09T16:32:01+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/"},"wordCount":1111,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1280x655.png","articleSection":["Emerging Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/","url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/","name":"Emerging Threat: (CVE-2026-58048) cPanel & WHM Database Privilege Escalation via Database Rename | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240-1280x655.png","datePublished":"2026-08-09T16:29:07+00:00","dateModified":"2026-08-09T16:32:01+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#primaryimage","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/image-240.png","width":1982,"height":1014},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-58048-cpanel-whm-database-privilege-escalation-via-database-rename\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Emerging Threat: (CVE-2026-58048) cPanel &#038; WHM Database Privilege Escalation via Database Rename"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3","name":"Igal Zeifman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","caption":"Igal Zeifman"},"description":"VP of Marketing","url":"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=2781"}],"version-history":[{"count":4,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2781\/revisions"}],"predecessor-version":[{"id":2789,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2781\/revisions\/2789"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=2781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=2781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=2781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}