Cyber Security News

Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server

Multiple security flaws in cPanel & WHM could let attackers run malicious scripts in an administrator’s browser session or execute arbitrary commands as root. The vulnerabilities were disclosed on September 29, 2026, and affect all supported cPanel & WHM versions before the vendor’s patched releases.

Administrators should update immediately, as a successful attack against the command-execution flaw could expose every hosting account, website, database, and service hosted on an affected machine. The most severe issue, CVE-2026-93698, affects the Multilang adminbin component and can result in full server compromise.

CVE-2026-93029 is a stored cross-site scripting vulnerability in the WHM Manage SSL Hosts interface. An unprivileged account holder may be able to store malicious script content that executes when a WHM administrator later views the affected interface.

Because the script runs within the administrator’s authenticated browser session, an attacker could potentially perform actions with the same permissions available to that administrator. This may include modifying server settings, managing accounts, or changing SSL-related configurations.

A second stored XSS issue, tracked as CVE-2026-93697, affects the WHM Mass Modify Accounts interface. Like the Manage SSL Hosts vulnerability, exploitation requires storing malicious content and later opening it as a WHM administrator. The flaw allows code to execute in the administrator’s session context, enabling administrative actions on the targeted user’s behalf.

Multiple Cpanel/WHM Vulnerabilities

The most serious vulnerability is CVE-2026-93698, which is caused by insufficient validation in the Multilang adminbin component. According to cPanel’s advisory, this weakness allows arbitrary command execution. It can lead to code execution as the root user.

Root-level command execution presents a major risk in shared-hosting and managed-server environments. An attacker with root access can read or alter data across all hosted accounts, install persistent malware, create unauthorized users, steal credentials, turn off security tools, and modify server configurations.

Unlike the two XSS vulnerabilities, which rely on an administrator viewing malicious stored content, the Multilang adminbin flaw directly concerns command execution. Security teams should treat it as an urgent patching priority because compromise of the underlying server can affect every customer and workload running on the system.

No public proof-of-concept exploit code was identified in the available vulnerability-tracking information at the time of reporting. However, the availability of technical advisory details may increase attacker interest, particularly where internet-exposed WHM interfaces have not been updated.

All supported cPanel & WHM versions are affected until upgraded to 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11, or WP2 11.138.1.13, or later. The same patched version set applies to CVE-2026-93029, CVE-2026-93697, and CVE-2026-93698, based on the disclosed product-version information.

Administrators should update cPanel & WHM to the latest available patched release as soon as possible. Organizations should also review WHM administrator activity, account changes, authentication logs, newly created privileged users, cron jobs, and unexpected modifications to server or hosting-account settings.

Restrict WHM access through firewall rules, VPN access, IP allowlists, and multi-factor authentication. Hosting providers should also review the privileges granted to lower-level account holders and investigate suspicious input submitted through SSL-host management, account-modification, or Multilang-related functions.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

25 minutes ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

2 hours ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

2 hours ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

2 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

2 hours ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

3 hours ago