---
id: CVE-2026-58048
title: >-
  Improper preservation of SQL mode when renaming databases in  cPanel allows
  execution of SQL in root context.
summary: >-
  Improper preservation of SQL mode when renaming databases in  cPanel allows
  execution of SQL in root context.
severity: none
cwe:
  - CWE-89
published: '2026-07-31'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-58048'
references:
  - url: 'https://docs.cpanel.net/changelogs/138-change-log'
    label: support@hackerone.com
  - url: >-
      https://support.cpanel.net/hc/en-us/articles/42285745783703-CVE-2026-58048-Database-Privilege-Escalation
    label: support@hackerone.com
tags:
  - nvd
  - exploit-available
epss: 0.00561
epssPercentile: 0.44247
ingestedAt: '2026-08-02T00:16:16.293Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/tc4dy/CVE-2026-58048-PoC-Exploit'
    - 'https://github.com/imbas007/POC-CVE-2026-58048'
  checkedAt: '2026-09-25T08:21:04.723Z'
exploitAvailable: true
---

## Overview

Improper preservation of SQL mode when renaming databases in  cPanel allows execution of SQL in root context.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
