# cPanel's Database Renaming Bug Hands Hosting Customers the Root Keys
## The Threat
cPanel has shipped an emergency security release plugging a privilege escalation that let any authenticated hosting customer run SQL commands with full database administrative rights — the same level of access the server's root database user holds. That boundary, between a paying customer's account and the underlying server infrastructure, is the foundational trust assumption that makes shared hosting work. CVE-2026-58048 breaks it.
The defect lives in cPanel's database-renaming routine. When a cPanel account renames a MySQL or MariaDB database, the system builds a replacement database, migrates the original data, recreates stored procedures and grants, then removes the old database. At some point in that sequence, the current SQL mode stops being enforced. The result is that SQL executes under the database's administrative context rather than the constrained, per-account privileges cPanel normally enforces. The HackerOne CNA record classifies this as CWE-89 — SQL injection — while cPanel's own advisory calls it a privilege escalation. Both descriptions are accurate; they're describing the same defect from different angles.
The vendor warns that depending on OS and database engine configuration, exploitation may extend to operating-system-level compromise. CISA's August 4 enrichment rates the technical impact as "total" while logging no confirmed exploitation — but that's a snapshot taken the same day the patch dropped, not a sustained assessment.
## Severity and Impact
| CVE | CVSS Score | Standard | Attack Vector | Complexity | Authentication | CWE |
|-----|-----------|----------|--------------|------------|----------------|-----|
| CVE-2026-58048 | 9.4 | CVSS 4.0 | Network | Low | Required (cPanel account) | CWE-89 |
| CVE-2026-58047 | 5.6 | CVSS 4.0 | Network | High | None | N/A |
CVE-2026-58048 is the critical database privilege escalation: authenticated cPanel users with MySQL/MariaDB feature access can execute arbitrary SQL as the database administrative user, with potential OS-level impact.
CVE-2026-58047 is an HTTP request-smuggling vulnerability in cpsrvd, the daemon serving the cPanel and WHM interfaces. An unauthenticated remote attacker can, under limited conditions, manipulate responses delivered to other users on the same server, potentially leaking credentials.
A third advisory covers a local privilege escalation in Exim via .forward file processing — content from that advisory was truncated in the source material; consult the cPanel security page for full details.
## Affected Products
CVE-2026-58048 and CVE-2026-58047 — patched in:
All supported versions of cPanel & WHM and WP Squared prior to these builds are vulnerable.
## Mitigations
Update immediately. Run the following from the command line or update through WHM:
/usr/local/cpanel/scripts/upcp --forceIf immediate patching isn't possible:
For CVE-2026-58048 (database root SQL execution):
For CVE-2026-58047 (request smuggling in cpsrvd):
cpsrvd_keepalives_disabled=1 in /var/cpanel/cpanel.config and restart cpsrvd. This forces a fresh TCP and TLS connection per request on ports 2083, 2087, and 2096. Expect increased latency and CPU consumption on high-traffic servers — this workaround has real operational cost, which is why patching is strongly preferred.Both CVEs were reported by researcher Vincent55 Yang.
## References
---
## HackWire Analysis
The most important number in this advisory isn't the 9.4 CVSS score — it's the population of people who can actually pull the trigger. On a shared hosting server selling accounts to strangers, every customer is a potential attacker. On a server where all accounts belong to one company's developers, the realistic threat surface is a fraction of that. The vendor advisory doesn't make this distinction, and neither do the breathless write-ups treating this as a universal critical emergency.
That said, CISA's "total" technical impact rating deserves to be taken seriously. A hosting customer who achieves database root access on a shared server has, in practical terms, access to every other customer's database on that machine. Shared hosting tables tend to be full of credentials, PII, and payment-adjacent data. The blast radius isn't one compromised account — it's every account on the box.
What makes this bug interesting technically is where it lives: not in some edge-case API or obscure feature, but in the routine act of renaming a database. The rename operation is a housekeeping function customers use regularly. The SQL mode bug was apparently invisible precisely because renaming a database is not an obvious attack surface. It took an external researcher to think about what actually happens during that sequence and realize the privilege boundary disappears mid-operation.
The request-smuggling issue in cpsrvd is less severe but notable for a different reason: it's unauthenticated. Combined with CVE-2026-58048, an attacker could potentially use the smuggling path to harvest credentials, then use those credentials to exploit the database bug. Neither advisory says this chain is practical, but it's the kind of pairing that incident responders will want to consider. Patch both, in the same window, today.
Shared hosting providers who run reseller operations — where accounts can be created, transferred, or phished — should treat this as a higher priority than a single-tenant deployment would.
— HackWire Editorial
---
## Related Coverage