CVE-2026-58047Disclosure

MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-08-01); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-07-31: 1Mentions · 2026-08-01: 2Mentions · 2026-08-04: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Active Exploitation · 2026-07-31: 1Active Exploitation · 2026-08-05: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-08-01: 2Technical Details · 2026-08-04: 1Technical Details · 2026-08-06: 107-3108-0108-0408-0508-06
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
Active Exploitation
116.7%
General
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-07-311
Active Exploitation1
2026-08-012
Disclosure1General1
2026-08-041
Disclosure1
2026-08-051
Patch1
2026-08-061
Patch1
Full discourse6 posts
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-58048 lets cPanel users run SQL commands in root context, CVSS 9.4. A second flaw, CVE-2026-58047, enables request smuggling. #cPanel #WHM #CVE202658048 #SQLInjection #PrivilegeEscalation #CyberSecurity http://securityonline.info/cve-2026-58048-cpanel-root-sql-execution/

    Post summary

    The post announces two new cPanel vulnerabilities: CVE-2026-58048 permits root SQL execution with a CVSS score of 9.4, while CVE-2026-58047 enables request smuggling.

    0603031.6K
    12.9K followersView on X
  • JeromeUG🇺🇬@jeromeug_
    Patch

    If you're on shared CPanel hosting: - Ask your host in writing whether CVE-2026-58048 is patched on YOUR server. Get the build number - Patch CVE-2026-58047 too - Confirm you closed CVE-2026-41940 in April; that one was exploited in the wild - Rotate credentials AFTER patching.

    Post summary

    The text advises shared cPanel hosts to verify patch status for CVE‑2026‑58048, CVE‑2026‑58047, and confirm the CVE‑2026‑41940 patch, noting it had been exploited in the wild, and to rotate credentials afterward.

    1000046
    1.3K followersView on X
  • ThaiCERT By NCSA@ThaiCERTByNCSA
    Patch

    เตือนช่องโหว่ใน cPanel & WHM และ WP Squared เสี่ยงรันคำสั่งฐานข้อมูลด้วยสิทธิ์ระดับผู้ดูแลระบบ ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์แห่งชาติ (ThaiCERT) พบรายงานการเปิดเผยช่องโหว่ใน cPanel & WHM และ WP Squared ที่หมายเลข CVE-2026-58048 ซึ่งเป็นช่องโหว่ระดับ Critical ที่ทำให้ผู้ใช้งาน cPanel ที่ผ่านการยืนยันตัวตนและมีสิทธิ์ใช้งาน MySQL/MariaDB สามารถรันคำสั่งฐานข้อมูลด้วยสิทธิ์ของผู้ดูแลระบบฐานข้อมูลได้ ส่งผลให้เกิดการยกระดับสิทธิ์จากบัญชี cPanel ไปเป็นสิทธิ์ระดับผู้ดูแลระบบฐานข้อมูล และอาจนำไปสู่การเข้าถึงหรือแก้ไขข้อมูลโดยไม่ได้รับอนุญาต[1] 1. รายละเอียดช่องโหว่ ช่องโหว่ CVE-2026-58048 (CVSS v4.0: 9.4)[2] ส่งผลกระทบต่อ cPanel & WHM เวอร์ชันที่ยังไม่ได้รับการแก้ไข รวมถึง WP Squared โดยการโจมตีต้องอาศัยบัญชี cPanel ที่ถูกต้องและมีสิทธิ์เข้าถึงฟีเจอร์ MySQL/MariaDB ผู้โจมตีอาจรันคำสั่งฐานข้อมูลด้วยสิทธิ์ระดับผู้ดูแลระบบฐานข้อมูล และในบางกรณีอาจขยายผลไปถึงการบุกรุกระดับระบบปฏิบัติการได้ ขึ้นอยู่กับระบบปฏิบัติการและการตั้งค่าฐานข้อมูลของเครื่องแม่ข่าย ช่องโหว่นี้เกี่ยวข้องกับกระบวนการเปลี่ยนชื่อฐานข้อมูลของ cPanel โดยข้อมูลจาก CNA ระบุว่า SQL mode ไม่ถูกคงค่าไว้อย่างเหมาะสมระหว่างการเปลี่ยนชื่อฐานข้อมูล ทำให้คำสั่ง SQL ถูกรันในบริบทของผู้ดูแลระบบฐานข้อมูล ทั้งนี้ cPanel advisory ระบุช่องโหว่ดังกล่าวในมุมของ privilege escalation ขณะที่ CNA จัดประเภทเป็น CWE-89 หรือ SQL Injection 2. ผลิตภัณฑ์ที่ได้รับผลกระทบ[3] 2.1 cPanel & WHM ทุกเวอร์ชันที่ได้รับการสนับสนุนและยังไม่ได้อัปเดตเป็น build ที่แก้ไขแล้ว 2.2 WP Squared เวอร์ชันที่ยังไม่ได้อัปเดตเป็น build ที่แก้ไขแล้ว 3. เวอร์ชันที่ได้รับการแก้ไขโดย cPanel ได้เผยแพร่อัปเดตแล้วในเวอร์ชันและหมายเลข Build ต่อไปนี้ - 11.110.0.137 - 11.118.0.71 - 11.126.0.78 - 11.134.0.48 - 11.136.0.32 - 138.1.6 สำหรับ WP Squared 4. ช่องโหว่ที่ควรตรวจสอบเพิ่มเติม นอกจาก CVE-2026-58048 ยังมีช่องโหว่อื่นที่ควรตรวจสอบ ดังต่อไปนี้[4] 4.1 CVE-2026-58047 เป็นช่องโหว่ HTTP Request Smuggling ใน cpsrvd อาจทำให้ผู้โจมตีที่ไม่ผ่านการยืนยันตัวตนสามารถปรับเปลี่ยน response ที่ส่งไปยังผู้ใช้งานรายอื่นบนเครื่องแม่ข่ายเดียวกัน และอาจทำให้ข้อมูลยืนยันตัวตนรั่วไหลได้ 4.2 ช่องโหว่ใน Exim ที่เกี่ยวข้องกับไฟล์ .forward ของผู้ใช้ภายในระบบ ซึ่งอาจทำให้เกิด unsafe string expansion ใน redirect router ภายใต้การตั้งค่า pipe transport บางรูปแบบ และอาจทำให้เกิดการยกระดับสิทธิ์จาก Team User sub-accounts ได้ 5. ผลกระทบที่อาจเกิดขึ้น 5.1 ผู้ใช้งาน cPanel ที่ผ่านการยืนยันตัวตนอาจรันคำสั่งฐานข้อมูลด้วยสิทธิ์ระดับผู้ดูแลระบบฐานข้อมูลได้ 5.2 ข้อมูลในฐานข้อมูลของผู้ใช้งานรายอื่นหรือข้อมูลระบบอาจถูกเข้าถึง แก้ไข หรือลบโดยไม่ได้รับอนุญาต 5.3 ระบบ shared hosting ความเสี่ยงอาจสูงขึ้น เนื่องจากมีผู้ใช้งานหลายรายอยู่บนเครื่องแม่ข่ายเดียวกัน 5.4 ผู้โจมตีอาจใช้ช่องโหว่ร่วมกับการตั้งค่าฐานข้อมูลหรือระบบปฏิบัติการบางรูปแบบ เพื่อขยายผลไปสู่การควบคุมระบบในระดับที่สูงขึ้น 5.5 ช่องโหว่ที่เกี่ยวข้องกับ cpsrvd และ Exim อาจเพิ่มความเสี่ยงต่อการรั่วไหลของข้อมูลยืนยันตัวตน การข้ามขอบเขตสิทธิ์ระหว่างผู้ใช้งาน หรือการยกระดับสิทธิ์ภายในระบบ 6. แนวทางการป้องกันและแก้ไข 6.1 เร่งอัปเดต cPanel & WHM และ WP Squared เป็นเวอร์ชันที่ได้รับการแก้ไขแล้ว 6.2 ผู้ดูแลระบบสามารถอัปเดตผ่าน WHM หรือใช้คำสั่ง /usr/local/cpanel/scripts/upcp --force ตามแนวทางของ cPanel 6.3 หากยังไม่สามารถอัปเดตได้ทันที ให้พิจารณาถอดสิทธิ์การใช้งานฟีเจอร์ MySQL/MariaDB จากบัญชี cPanel ชั่วคราว โดยฐานข้อมูลเดิมจะยังทำงานอยู่ แต่ผู้ใช้งานจะไม่สามารถเพิ่มหรือลบฐานข้อมูลได้ 6.4 สำหรับช่องโหว่ CVE-2026-58047 หากยังไม่สามารถอัปเดตได้ทันที ให้พิจารณาปิด backend connection reuse ของ cpsrvd ตามคำแนะนำของ cPanel โดยต้องพิจารณาผลกระทบด้าน latency และการใช้ CPU บนเครื่องแม่ข่ายที่มีปริมาณใช้งานสูง 6.5 ตรวจสอบบัญชี cPanel, Team User sub-account และบัญชีฐานข้อมูลที่มีสิทธิ์ผิดปกติ โดยเฉพาะระบบ shared hosting หรือระบบที่ให้ลูกค้าภายนอกใช้งาน 6.6 ตรวจสอบ log ของ cPanel, WHM, MySQL/MariaDB และ Exim เพื่อค้นหาคำสั่งฐานข้อมูลผิดปกติ การเปลี่ยนชื่อฐานข้อมูล การแก้ไขสิทธิ์ฐานข้อมูล หรือพฤติกรรมที่อาจบ่งชี้การยกระดับสิทธิ์ 6.7 จำกัดการเข้าถึง WHM/cPanel interface เฉพาะเครือข่ายที่ได้รับอนุญาต และเปิดใช้งาน MFA สำหรับบัญชีผู้ดูแลระบบและบัญชีผู้ใช้งานที่มีสิทธิ์สูง 6.8 สำรองข้อมูลสำคัญและตรวจสอบความสมบูรณ์ของฐานข้อมูลหลังอัปเดต โดยเฉพาะเครื่องแม่ข่ายที่ให้บริการ shared hosting แหล่งอ้างอิง 1. https://dg.th/p4e6bfdk8z 2. https://dg.th/coa23klhie 3. https://dg.th/zvlbfn8git 4. https://dg.th/abg1rol9j6 กรณีพบเหตุการณ์ภัยคุกคามทางไซเบอร์หรือพฤติกรรมน่าสงสัย Email: thaicert@ncsa.or.th โทร. 02 114 3531 ตลอด 24 ชั่วโมง

    Post summary

    Thai CERT released a security advisory for CVE‑2026‑58048, detailing a critical privilege‑escalation flaw in cPanel/WHM and WP Squared, providing patch build information and mitigation steps.

    00000140
    62 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58047 HTTP Smuggling in cPanel allows potential leak of credentials. https://www.cve.org/CVERecord?id=CVE-2026-58047 ----- Traducción: CVE-2026-58047: HTTP Smuggling en cPanel permite posible filtración de credenciales. https://www.cve.org/CVERecord?id=CVE-2026-58047 Fuente: `CVEnew… http://infoflow.cloud`

    Post summary

    CVE-2026-58047 discloses an HTTP Smuggling flaw in cPanel that could leak credentials; no PoC, exploit code, patches, or active exploitation details are present.

    0000042
    96 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-58047 HTTP Smuggling in cPanel allows potential leak of credentials. https://www.cve.org/CVERecord?id=CVE-2026-58047

    Post summary

    A brief note references CVE‑2026‑58047, noting HTTP smuggling could leak credentials, with only a link to the CVE record and no further actionable details.

    000001.9K
    57.9K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting WebPros cPanel and WP Squared (CVE-2026-58047) https://vuldb.com/vuln/385109/cti

    Post summary

    The post indicates that attackers are increasingly targeting WebPros cPanel and WP Squared via CVE-2026-58047, suggesting active exploitation in the wild, but provides no mitigation or technical details.

    00000112
    2.3K followersView on X

Explore more