Threat reportVulnerabilityTL-2026-1862
CVE-2026-58048 — cPanel & WHM Database Privilege Escalation via Database Rename (SQL Mode Loss)
CVE-2026-58048 (TL-2026-1862), also tracked as GHSA-xgvx-cwxw-9vpj, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-08-04. It has no confirmed attribution, affects WebPros (cPanel) cPanel & WHM, references 1 CVE (CVE-2026-58048), maps to 11 MITRE ATT&CK techniques (T1005, T1048, T1059), and is covered by 9 detection rules and 5 indicators of compromise.
- CVSS
- 9.4/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 5Indicators of compromise
Key facts for TL-2026-1862
- Threat ID
- TL-2026-1862
- Also known as
- GHSA-xgvx-cwxw-9vpj
- Severity
- CRITICAL
- CVSS
- 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- web-hosting, managed-wordpress, cloud-infrastructure, saas, shared-hosting, reseller-hosting
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 5
Malware and tooling in CVE-2026-58048
Malware and tooling: MySQL/MariaDB database server, WP Squared Managed WordPress (vulnerable builds), cPanel & WHM (vulnerable builds), cPanel Feature Manager (WHM)
How CVE-2026-58048 works
A critical privilege escalation vulnerability in cPanel & WHM (all supported version tiers) and WP Squared allows an authenticated low-privileged cPanel user to escalate to full database administrator access by renaming a database. The SQL mode is not preserved during the rename, enabling SQL commands to execute with root-level database authority. Depending on the operating system and database engine configuration, this may extend to operating-system-level compromise. Fixed builds are available across all supported release tiers.
CVE-2026-58048 is a critical SQL injection vulnerability discovered by security researcher Vincent55 Yang (via HackerOne) in WebPros' cPanel, WHM, and WP Squared products. The flaw carries a CVSS 4.0 base score of 9.4 (CRITICAL) with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, indicating network-based exploitation with low complexity, no attack requirements, low privileges required, no user interaction, and high impact on confidentiality, integrity, and availability with scope change to subsequent systems. The CNA record classifies this as CWE-89 (SQL Injection), while the cPanel advisory describes it as a privilege escalation bug — both characterize the same underlying flaw.
The root cause lies in the improper preservation of SQL mode during the database rename workflow in cPanel. When a user initiates a database rename, cPanel's root-owned daemon performs the following sequence: (1) builds a replacement database, (2) migrates the data over, (3) recreates grants and stored code, and (4) deletes the original database and its permissions. During this process, the SQL mode (a MySQL/MariaDB server setting that controls SQL syntax behavior and operational constraints) is not correctly re-applied to the replacement database. This creates a window where an attacker-influenced input in the rename path is interpreted by the MySQL/MariaDB server with root-level database privileges rather than the confined low-privileged user context, enabling arbitrary SQL execution.
cPanel is a Linux-based web-hosting control panel that brokers unprivileged user actions (such as database creation, renaming, and deletion) into privileged operations performed by root-owned daemons against the underlying MySQL/MariaDB server. The vulnerability exists in this root-context daemon path where the rename operation fails to preserve the SQL mode. The discrepancy between the cPanel advisory (privilege escalation) and the CNA classification (CWE-89 SQL Injection) reflects the same technical reality: the SQL mode loss during rename enables root-level SQL injection through a mechanism that manifests as privilege escalation.
The vulnerability affects all supported cPanel & WHM version tiers prior to the respective fixed builds: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, and 11.136.0.32, as well as version 11.137.9999.99. WP Squared (WebPros' managed-WordPress hosting platform) is also affected prior to build 11.138.1.6, as it shares the same vulnerable code path. The prerequisite for exploitation is a valid cPanel account with the MySQL/MariaDB feature enabled. It remains unclear whether Team User sub-accounts (delegated limited-permission logins) qualify as exploit-capable authenticated holders — this is an open question that should be verified with cPanel support.
The CISA SSVC assessment (via the vulnrichment program) reports no known exploitation observed in the wild as of August 1, 2026, and assesses the vulnerability as not automatable but with total technical impact. The EPSS score is 0.503% (40th percentile), indicating low predicted exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the 'Critical' severity designation reflects the potential impact, not current exploitation volume — if exploited, the attacker gains full read/write/delete access to all databases on the server, with potential for OS-level compromise depending on database engine configuration (e.g., MySQL/MariaDB's LOAD DATA INFILE, SELECT INTO OUTFILE, or user-defined function capabilities that can execute OS commands).
Fixed builds have been released across all supported cPanel & WHM release tiers. The primary remediation is to upgrade to the cPanel 138 release series or the specific patched builds listed above. Enabling cPanel's automatic-update mechanism will pick up the patched tier on the standard release cadence. As a compensating control, administrators can temporarily revoke the MySQL/MariaDB feature from cPanel users (which does not disable existing databases — it only prevents creation and removal of databases) or restrict database rename permissions to trusted administrators. On shared hosting environments, patching should be prioritized for nodes with numerous or untrusted tenants to reduce the exposure window. Auditing recent database rename operations for suspicious activity is also recommended.
MITRE ATT&CK techniques used in TL-2026-1862
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Execution
T1059 Command and Scripting Interpreter
Discovery
T1082 System Information Discovery; T1087 Account Discovery
Impact
T1485 Data Destruction; T1565 Data Manipulation
Persistence
T1505 Server Software Component
Credential Access
defense-impairment
Affected products and versions in CVE-2026-58048
- WebPros (cPanel) — cPanel & WHM
Vulnerable versions: All versions < 11.110.0.137 (110 tier); All versions < 11.118.0.71 (118 tier); All versions < 11.126.0.78 (126 tier); All versions < 11.134.0.48 (134 tier); All versions < 11.136.0.32 (136 tier); 11.137.9999.99
Fixed in: 11.110.0.137; 11.118.0.71; 11.126.0.78; 11.134.0.48; 11.136.0.32; 138 release series and later - WebPros (WP Squared) — WP Squared Managed WordPress
Vulnerable versions: All versions < 11.138.1.6
Fixed in: 11.138.1.6 and later
Remediation for CVE-2026-58048
Patches
- Upgrade cPanel & WHM to build 11.110.0.137 (110 tier), 11.118.0.71 (118 tier), 11.126.0.78 (126 tier), 11.134.0.48 (134 tier), or 11.136.0.32 (136 tier) depending on your release tier
- Upgrade to the cPanel 138 release series for the latest patched build
- Upgrade WP Squared to build 11.138.1.6 or later
Immediate actions
- Revoke the MySQL/MariaDB feature from cPanel users as a temporary compensating control (does not disable existing databases, only prevents creation/removal)
- Restrict database rename permissions to trusted administrators only
- Audit recent database rename operations for suspicious activity
Workarounds
- Edit cPanel feature lists to disable the 'MySQL' feature for all non-admin users (via WHM: Feature Manager)
- Temporarily disable database rename capability until patching is complete
- Isolate shared hosting tenants on separate database instances where feasible
Longer-term hardening
- Enable cPanel's automatic-update mechanism to ensure timely patch delivery
- Implement a vulnerability management process for shared hosting infrastructure
- Consider network segmentation isolating database servers from tenant-facing control planes
- Implement database activity monitoring (DAM) for shared hosting environments
CVEs associated with CVE-2026-58048
Weaknesses (CWE) in CVE-2026-58048
Timeline of CVE-2026-58048
- CVE-2026-58048 reserved by HackerOne (CNA) for the cPanel database privilege escalation vulnerability reported by Vincent55 Yang
- GitHub Advisory Database publishes GHSA-xgvx-cwxw-9vpj covering CVE-2026-58048 with CVSS 4.0 score 9.4 and EPSS score of 0.503%
- cPanel 138 release series and individual fixed builds (11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32) released addressing the database rename privilege escalation. WP Squared fixed build 11.138.1.6 also released
- CVE-2026-58048 published to the NVD and CVE list with a CVSS 4.0 base score of 9.4 (CRITICAL). cPanel released official advisory and fixed builds across all supported release tiers
- CISA ADP updates the vulnrichment record with SSVC assessment: no exploitation observed, not automatable, total technical impact
- Security Affairs publishes detailed article on CVE-2026-58048, bringing the vulnerability to broader public attention, noting potential for OS-level compromise under certain configurations
Sources cited for CVE-2026-58048
- Security Affairs — CVE-2026-58048: cPanel bug enables full database administrator access
- cPanel Official Advisory — CVE-2026-58048 Database Privilege Escalation
- NVD Detail — CVE-2026-58048
- GitHub Advisory — GHSA-xgvx-cwxw-9vpj
- CISA Vulnrichment — CVE-2026-58048 SSVC Assessment
- cPanel 138 Change Log
- CVE.org Record — CVE-2026-58048
Detection coverage for TL-2026-1862
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1862 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.