CVE-2026-58048: cPanel & WHM Database Privilege Escalation Vulnerability
Hosting environments run on a basic assumption: an account with limited permissions should stay limited. CVE-2026-58048 breaks that assumption inside cPanel & WHM. Any authenticated account with MySQL or MariaDB feature access, including a standard low-privilege hosting account, can now escalate to root-level database privileges through a database rename operation. A public proof-of-concept already exists, which means the barrier to exploitation is low and the window to act is short.