CVE-2026-58048Disclosure

CRITICAL

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

8.3/ 10 priority

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 57 mentions across 9 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 26 signals
  • Technical details provided in 46 signals
  • Disclosure: 25 classified signals
  • General: 4 classified signals
  • Peaked 5d ago at 29 mentions (2026-08-04); latest day: 1
  • 57 total mentions across 9 days

Deep dive

Activity timeline57 mentions / 9d
07152229Mentions · 2026-07-31: 1Mentions · 2026-08-01: 3Mentions · 2026-08-03: 1Mentions · 2026-08-04: 29Mentions · 2026-08-05: 13Mentions · 2026-08-06: 6Mentions · 2026-08-07: 2Mentions · 2026-08-12: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-08-04: 2PoC Mentioned / Linked · 2026-08-05: 2PoC Mentioned / Linked · 2026-08-06: 2Exploit Tool / Code · 2026-08-05: 1Exploit Tool / Code · 2026-08-06: 2Active Exploitation · 2026-07-31: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-08-05: 1Patch / Workaround · 2026-08-01: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-04: 12Patch / Workaround · 2026-08-05: 9Patch / Workaround · 2026-08-06: 2Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-01: 3Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 25Technical Details · 2026-08-05: 10Technical Details · 2026-08-06: 5Technical Details · 2026-08-07: 1Technical Details · 2026-08-12: 107-3108-0108-0308-0408-0508-0608-0708-1209-11
Signal classification5 categories
Disclosure
2543.9%
Patch
2340.4%
General
47.0%
PoC
35.3%
Active Exploitation
23.5%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-311
Active Exploitation1
2026-08-013
Disclosure2Patch1
2026-08-031
Patch1
2026-08-0429
Active Exploitation1Disclosure16General1Patch10PoC1
2026-08-0513
Disclosure4General1Patch8
2026-08-066
Disclosure2Patch2PoC2
2026-08-072
Disclosure1General1
2026-08-121
Patch1
2026-09-111
General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    ‼️ WARNING - A new critical cPanel flaw could let shared hosting customers run SQL as database root, bypassing database privilege boundaries. CVE-2026-58048 (CVSS 9.4) affects supported cPanel & WHM versions and WP Squared. In some configurations, impact may extend to OS-level compromise. Details: https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

    Post summary

    A new critical cPanel flaw (CVE-2026-58048, CVSS 9.4) allows shared‑hosting customers to run SQL as database root and may lead to OS‑level compromise.

    1010442738358.1K
    2.3M followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-58048 (CVSS 9.4): Improper SQL mode preservation during database rename in cPanel allows an authenticated cPanel account holder to execute arbitrary SQL with root privileges — full server compromise in shared hosting environments. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJjUGFuZWwtTUdNVC1Qcm9kdWN0cyI= 🎯32.6M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="cPanel-MGMT-Products" 🔖Refer: https://securityonline.info/cve-2026-58048-cpanel-root-sql-execution/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post discloses a high‑severity (CVSS 9.4) SQL injection flaw in cPanel that lets authenticated users gain root privileges, providing a brief technical description and FOFA query references but no exploit code, active exploitation claims, or patch information.

    02811024113.0K
    14.8K followersView on X
  • elhacker.NET@elhackernet
    Patch

    Grave fallo en cPanel permitiría a usuarios de hosting ejecutar SQL como root de la base de datos cPanel ha corregido tres vulnerabilidades críticas, destacando la CVE-2026-58048 que permitía a usuarios autenticados ejecutar comandos SQL https://blog.elhacker.net/2026/08/grave-fallo-en-cpanel-permitiria.html

    Post summary

    The Spanish post announces that cPanel has fixed a critical SQL‑execution flaw (CVE‑2026‑58048) affecting authenticated users, highlighting the availability of a patch.

    028178197.6K
    141.8K followersView on X
  • The Hacker News@TheHackersNews
    Disclosure

    In case you missed it >>> A flaw in cPanel’s database-renaming process could let a hosting customer run SQL as database root. CVE-2026-58048 affected every supported cPanel & WHM version. In some configurations, the impact could extend to OS-level compromise. Read: https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

    Post summary

    CVE-2026-58048 is a critical flaw in cPanel’s database-renaming process that may allow a hosting customer to execute SQL as the database root, and in some configurations could lead to OS-level compromise.

    1101581324.5K
    2.3M followersView on X
  • Agencia Nacional de Ciberseguridad (ANCI)@ANCIChile
    Patch

    🚨 Desde la Agencia Nacional de Ciberseguridad (#ANCI) compartimos información de una nueva vulnerabilidad que afecta a #cPanel, identificada como CVE-2026-58048: https://csirt.gob.cl/alertas/avc26-00727/ 🩹 ¡Actualiza ahora! https://t.co/k43IXTbA5e

    Post summary

    The ANCI alert announces a new cPanel vulnerability (CVE-2026-58048) and urges users to apply the latest updates.

    019043124.7K
    17.8K followersView on X
  • Cyber Advising@cyber_advising
    PoC

    CVE-2026-58048: cPanel Root SQL Execution Toolkit Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. PoC https://github.com/tc4dy/CVE-2026-58048-PoC-Exploit/tree/main https://t.co/qPL7ZOXICN

    Post summary

    A proof‑of‑concept exploit demonstrating root‑level SQL injection via cPanel’s insufficient SQL mode handling, with a GitHub repository linked for the code.

    13029182.1K
    13.6K followersView on X
  • ThreatWire@ThreatWire_
    Disclosure

    🚨 CVE-2026-58048 (CVSS 9.4): A critical cPanel & WHM vulnerability could let shared hosting users execute SQL as the database root, bypassing privilege boundaries. In some configurations, the flaw may lead to OS-level compromise. #cPanel #CVE #CyberSecurity #Hosting

    Post summary

    The tweet announces a critical cPanel & WHM vulnerability (CVE-2026-58048) that allows shared hosting users to run SQL as root and potentially achieve OS‑level compromise.

    02030102.7K
    1.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-58048 lets cPanel users run SQL commands in root context, CVSS 9.4. A second flaw, CVE-2026-58047, enables request smuggling. #cPanel #WHM #CVE202658048 #SQLInjection #PrivilegeEscalation #CyberSecurity http://securityonline.info/cve-2026-58048-cpanel-root-sql-execution/

    Post summary

    The excerpt announces two cPanel vulnerabilities, CVE‑2026‑58048 and CVE‑2026‑58047, highlighting their severity and providing a link for further details.

    0603031.6K
    12.9K followersView on X
  • اخبار داغ امنیت شبکه - تاکیان@Takianco
    Disclosure

    🔴 یک آسیب‌پذیری بحرانی با شناسه CVE-2026-58048 به کاربران دارای حساب cPanel اجازه می‌دهد دستورات SQL را با سطح دسترسی Root پایگاه‌داده اجرا کنند و به سطح سیستم‌عامل دسترسی پیدا کنند. #CyberSecurity #cPanel #ServerSecurity #MySQL #CVE202658048 https://www.takian.ir/news/new-%DB%8C%DA%A9-%D8%A8%D8%A7%DA%AF-%D8%A8%D8%AD%D8%B1%D8%A7%D9%86%DB%8C-%D8%AF%D8%B1-cpanel-%D9%85%DB%8C%E2%80%8C%D8%AA%D9%88%D8%A7%D9%86%D8%AF-%DA%A9%D9%86%D8%AA%D8%B1%D9%84-%DA%A9%D8%A7%D9%85%D9%84-%D9%BE%D8%A7%DB%8C%DA%AF%D8%A7%D9%87%E2%80%8C%D8%AF%D8%A7%D8%AF%D9%87-%D8%B1%D8%A7-%D8%A8%D9%87-%D9%85%D9%87%D8%A7%D8%AC%D9%85-%D8%A8%D8%AF%D9%87%D8%AF%D8%9B-%D8%AE%D8%B7%D8%B1-%D8%A7%D8%B1%D8%AA%D9%82%D8%A7%DB%8C-%D8%AF%D8%B3%D8%AA%D8%B1%D8%B3%DB%8C-%D8%AA%D8%A7-%D8%B3%D8%B7%D8%AD-%D8%B3%DB%8C%D8%B3%D8%AA%D9%85%E2%80%8C%D8%B9%D8%A7%D9%85%D9%84 https://t.co/mKQQUPEMQA

    Post summary

    The message announces the discovery of a critical cPanel vulnerability (CVE-2026-58048) that permits privileged database and operating‑system access. No exploit, patch, or active‑use evidence is disclosed.

    13073732
    643 followersView on X
  • CiberBaur@BotBauR
    Patch

    Acaba de descubrirse una vulnerabilidad crítica en cPanel, CVE-2026-58048, que permite a los usuarios autenticados ejecutar SQL como root. La empresa cPanel acaba de parchar esta falla, que tiene un CVSS score de 9.4, y que podría permitir el acceso no autorizado a bases de datos. La vulnerabilidad fue descubierta recientemente y afecta a versiones anteriores a la última actualización. Los atacantes podrían aprovechar esta vulnerabilidad para obtener acceso a información confidencial. Es crucial que los administradores de sistemas actualicen cPanel a la versión más reciente lo antes posible. ¿Estás en riesgo? Revisa esto: actualiza cPanel ahora y verifica los logs de acceso a tu base de datos. #Ciberseguridad #CVE #SeguridadDigital #Threat https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html

    Post summary

    La publicación anuncia la detección de una alta‑severidad vulnerabilidad en cPanel que permite ejecutar SQL como root, pero señala que cPanel ya ha lanzado un parche. Se recomienda actualizar inmediatamente.

    040811.0K
    628 followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Patch

    سی‌پنل (cPanel) یک آسیب‌پذیری حیاتی را با شناسه CVE-2026-58048 و امتیاز CVSS 9.4 وصله کرد که به مشتریان احراز هویت‌شده میزبانی اجازه می‌داد دستورات SQL را در بافت مدیریتی پایگاه داده (root context) اجرا کنند و از این طریق مرز امتیازات بین حساب cPanel و هویت مدیریتی سرور را نقض کنند. این نقص که تمام نسخه‌های پشتیبانی‌شده cPanel و WHM و همچنین WP Squared را تحت تأثیر قرار می‌دهد، در فرآیند تغییر نام پایگاه داده نهفته است؛ به گونه‌ای که حالت SQL هنگام تغییر نام حفظ نمی‌شود و دستورات در بافت root اجرا می‌شوند.

    Post summary

    cPanel has patched CVE-2026-58048, a critical SQL injection that could allow authenticated users to execute root‑level queries and escape privilege boundaries.

    00043713
    19.4K followersView on X
  • LowEndBox@LowEndNetwork
    Disclosure

    CVE-2026-58048 "Database Privilege Escalation" is making the rounds.  If you haven't seen it, be advised your cPanel is probably vulnerable.  It affects at least all supported versions. #cpanel #mysql https://bit.ly/45Hrbqw https://t.co/fDyCJtg7fA

    Post summary

    The tweet alerts that CVE‑2026‑58048, a database privilege escalation flaw, likely affects all supported cPanel versions, and includes a link for further details.

    02040406
    9.0K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Disclosure

    CVE-2026-58048: #cPanel Bug Enables Full Database Administrator Access. https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html #securityaffairs #hacking

    Post summary

    The tweet announces a cPanel vulnerability (CVE‑2026‑58048) that allows attackers to gain full database administrator privileges, but it provides no details on exploitation, patches, or active use.

    00041701
    37.7K followersView on X
  • JeromeUG🇺🇬@jeromeug_
    Disclosure

    CYBERSECURITY ADVISORY THREAD ALERT! Two warnings for Ugandan businesses in 24 hours. Next Media confirms NBS, AfroMobile & Next Radio social accounts were taken over. AfroMobile recovered; posts from the others aren't theirs. Separately: critical cPanel flaw (CVE-2026-58048, CVSS 9.4) lets a co-tenant on your shared server reach your database as root. Different attacks. Same lesson: your biggest exposure is the infrastructure and identities you don't fully control. Today's actions 👇

    Post summary

    The advisory announces the critical CVE-2026-58048 in cPanel, outlining its high impact (root database access on shared servers) and warns Ugandan businesses of related account takeovers.

    11020130
    1.3K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    【レンタルサーバ向け】cPanelで重大(Critical)な脆弱性が修正。CVE-2026-58048はCVSSスコア9.4で、rootでのSQLインジェクション。データベースの名前変更機能における不備に起因。 https://securityonline.info/cve-2026-58048-cpanel-root-sql-execution/

    Post summary

    The post announces that cPanel’s critical CVE-2026-58048 root SQL injection flaw (CVSS 9.4) has been fixed, highlighting that the issue originates from a bug in the database rename function and a patch is available.

    01030758
    7.8K followersView on X
  • EcuCERT@EcuCERT_EC
    Disclosure

    Vulnerabilidad crítica CVE-2026-58048 en cPanel/WHM permite a usuarios autenticados ejecutar consultas SQL con privilegios elevados en MySQL/MariaDB. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/08/Al-2026-039-Vulnerabilidad-critica-en-cPanel-y-WHM-permite-ejecucion-de-SQL-con-privilegios-de-root-CVE-2026-58048.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/pbZpbb9xz7

    Post summary

    An announcement in Spanish details CVE‑2026‑58048, a critical privilege‑escalation SQL flaw in cPanel/WHM, with a link to a PDF for additional information.

    00030347
    2.1K followersView on X
  • Modat@modat_magnify
    Patch

    ⚠️cPanel & WHM – Database Privilege Escalation (CVSS 9.4) cPanel has patched CVE-2026-58048, a critical privilege-escalation flaw in the database management feature of cPanel & WHM (and WP Squared). An authenticated customer with MySQL/MariaDB access can run arbitrary database commands as database root, crossing the boundary between a cPanel account and the server's root database identity. The flaw sits in the database-renaming process, where SQL mode is not preserved during a rename, causing SQL to run in root context. Depending on configuration, cPanel warns it may extend to OS-level compromise. Affected: All supported versions of cPanel & WHM, and WP Squared. Mitigation: Update to a patched build (11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, or WP Squared 138.1.6). Where patching must wait, temporarily revoke the MySQL feature from cPanel users. Modat Magnify Query: technology="cPanel" or web.title~"WP Squared Login" or web.headers~"whostmgrrelogin" The platform: https://magnify.modat.io/ #ModatMagnify #threatintel #vulnerability #CVE202658048 #cPanel #WHM #PrivEsc #SQLi #infosec #Critical

    Post summary

    The post announces that cPanel has released patches for CVE-2026-58048, a critical database privilege‑escalation flaw, and provides detailed vulnerability and mitigation information.

    01020364
    1.8K followersView on X
  • S.A.P@SAP127001
    Patch

    @TheHackersNews CVE-2026-58048 has been fixed. cPanel released patched versions on July 30-31 The following versions contain the fix: cPanel/WHM 11.110.0.137 cPanel/WHM 11.118.0.71 cPanel/WHM 11.126.0.78 cPanel/WHM 11.134.0.48 cPanel/WHM 11.136.0.32 WP Squared 138.1.6

    Post summary

    The post announces that CVE‑2026‑58048 has been fixed and provides the specific cPanel/WHM and WP Squared versions that contain the patch.

    00030332
    283 followersView on X
  • ./vitoocorleonné@esnaftech
    Disclosure

    cPanel'de CVE-2026-58048 zafiyeti (CVSS: 9.4) paylaşımlı hosting ortamlarını büyük bir tehlikeye atıyor. Kimliği doğrulanmış bir kullanıcı, veritabanı yeniden adlandırma sırasında "root" yetkileriyle SQL komutları çalıştırabiliyor. Sonuç: Sunucunun tamamen ele geçirilmesi! 👇

    Post summary

    The post announces the high‑severity CVE‑2026‑58048 in cPanel, explaining that an authenticated user can run root‐level SQL commands during database renaming, potentially allowing full server compromise.

    10020168
    91 followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na zranitelnost v cPanel & WHM, CVE-2026-58048. Zranitelnost s hodnocením CVSS 9.4 umožňuje autentizovanému uživateli hostingového účtu s přístupem k funkcím MySQL/MariaDB spouštět libovolné SQL příkazy v kontextu databázového uživatele root. Chyba se nachází v procesu přejmenování databáze, kde není správně zachován SQL režim, což může vést ke spuštění SQL v administrátorském kontextu. V závislosti na konfiguraci operačního systému a databázového enginu může dojít až ke kompromitaci operačního systému. Zranitelnost postihuje všechny podporované verze cPanel & WHM a WP Squared. 📌Doporučujeme aktualizovat na verzi 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32 nebo 138.1.6 pro WP Squared.

    Post summary

    The message alerts about CVE-2026-58048, details its high‑severity SQL injection flaw, and recommends specific patch versions to mitigate the risk.

    02000483
    4.2K followersView on X

Explore more