Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-58048-PoC-Exploit — 👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3 | Kitploit
Tools/GitHubGitHub/tc4dy/cve-2026-58048-poc-exploit
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration TestingRed TeamingIncident Response

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Database Security
GitHubtc4dy/cve-2026-58048-poc-exploit

CVE-2026-58048-PoC-Exploit

View Repository
521919h 17m agoNot yet reviewed

About

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3

Share

CVEPoC

CVE‑2026‑58048 – cPanel Root SQL Execution Toolkit

Python 3.8+ CVSS Author cPanel

ETHICAL USE ONLY – AUTHORIZED SECURITY TESTING
This repository provides tools for authorized security professionals, blue teams, and penetration testers only.
Unauthorized access to computer systems is illegal under CFAA (US), Computer Misuse Act (UK), TCK 243/244 (Turkey), and similar laws worldwide.


Vulnerability Overview

CVE‑2026‑58048 is a critical SQL injection vulnerability in cPanel & WHM versions 11.x that allows an authenticated cPanel user to execute arbitrary SQL commands with MySQL root privileges via the database rename functionality.

How it works

  1. Authenticated access required – the attacker must have a valid cPanel account (username/password) on the target server.
  2. SQL mode manipulation – the exploit sets the MySQL session to ANSI_QUOTES mode, which changes the parsing behavior.
  3. Database rename injection – when renaming a database, the new name is not properly sanitized, allowing the attacker to inject arbitrary SQL statements.
  4. Root privileges – because the rename operation runs with MySQL root privileges, the injected SQL is executed with the highest database permissions.
  5. Impact – full database takeover, privilege escalation, server compromise, data theft, backdoors, and lateral movement. Upgrade immediately!

Affected Versions

  • cPanel & WHM 11.110 and earlier – vulnerable
  • 11.111 – 11.118 – vulnerable
  • 11.119 – 11.126 – vulnerable
  • 11.127 – 11.134 – vulnerable
  • 11.135 – 11.136 – vulnerable
  • 11.137.x – vulnerable below 11.137.1.6
  • 11.138.1.6 and later – patched

Patch

  • Upgrade to cPanel & WHM 11.138.1.6 or newer.
  • If upgrade is not possible, disable MySQL rename operations for cPanel users as a temporary workaround.

Tools

ToolPurposeIntended User
exploit.pyFull weaponized toolkit with reverse shell, persistence, UDF RCE, file read/write, database operations, proxy support, and mass scanning.Red teams / authorized pentesters
safecheck.pyNon‑intrusive vulnerability checker that detects cPanel version and assesses risk without executing any malicious payload. Generates detailed reports.Blue teams / security auditors

Feature Comparison

Featureexploit.pysafecheck.py
Vulnerability detection[+][+]
Version detection[+][+]
MySQL root SQL injection[+][-]
Reverse shell[+][-]
Persistence (cPanel user creation)[+][-]
UDF RCE (command execution)[+][-]
File read/write[+][-]
Database operations (any SQL)[+][-]
Proxy support[+][+]
Mass scanning (multi‑thread)[+][-]
Interactive shell[+][-]
Non‑intrusive (safe) mode[-][+]
Verbose/Debug mode[+][+]
SSL verification control[+][+]
Custom User‑Agent[+][+]
Request delay / retries[+][-]
JSON / report output[+][+]
Endpoint accessibility check[-][+]
SQL mode leakage detection[-][+]

Use Case Summary

ScenarioRecommended Tool
Blue Team – verifying if your cPanel installation is vulnerablesafecheck.py
Security Audit – non‑intrusive vulnerability assessmentsafecheck.py
Red Team – authorized penetration testing with full exploitationexploit.py
Bug Bounty – responsible disclosure testingsafecheck.py
Mass Scanning – checking multiple targets for vulnerabilityexploit.py (detection only)
Incident Response – checking if systems are compromisedsafecheck.py

Installation

git clone https://github.com/tc4dy/CVE-2026-58048-PoC-Exploit
cd CVE-2026-58048
pip install -r requirements.txt

requirements.txt

requests
urllib3
colorama
pymysql

Parameters

exploit.py Parameters

ParameterDescription
-t, --targetTarget cPanel URL (e.g. https://cpanel.example.com:2083)
-l, --target-fileFile containing list of targets (one per line) for mass scanning
-u, --mysql-usercPanel/MySQL username
-P, --mysql-passcPanel/MySQL password
--mysql-portMySQL port (default: 3306)
-p, --portOverride cPanel port (default from URL or 2083)
--threadsNumber of threads for multi‑target (default: 10)
-o, --outputSave results to file (single target)
--logLog file for detailed output
-v, --verboseVerbose output
--proxyHTTP/HTTPS proxy (e.g. http://127.0.0.1:8080)
-ua, --user-agentCustom User‑Agent
--no-keep-aliveDo not keep session alive
--delayDelay between requests (default: 2.0s)
--max-retriesMax retries (default: 3)
--ssl-verifyVerify SSL certificates
--cmdCommand to execute (prefix with sql: or udf: for specific)
--injectCustom SQL to inject (overrides other actions)
--reverse-shellReverse shell IP:PORT (uses UDF)
--passwdChange root MySQL password
--adduserCreate cPanel user (USER DOMAIN PASSWORD)
--readRead a file via LOAD_FILE
-i, --interactiveInteractive shell after exploit
--verifyVerify exploit success by attempting MySQL login
--pingPing target before exploitation

safecheck.py Parameters

ParameterDescription
-t, --targetTarget cPanel URL (e.g. https://cpanel.example.com:2083)
-v, --verboseVerbose output
--proxyHTTP/HTTPS proxy (e.g. http://127.0.0.1:8080)
-ua, --user-agentCustom User‑Agent
--ssl-verifyVerify SSL certificates
--timeoutRequest timeout in seconds (default: 10)
--logSave report to file
--jsonOutput results in JSON format

Scenarios

Download Tool