Critical cPanel & WHM Flaws Let Attackers Run Commands
Key Takeaways Multiple critical vulnerabilities in cPanel & WHM, including remote code execution (RCE) and stored Cross-Site Scripting (XSS), were disclosed on September 29, 2026. The most severe...
Key Takeaways
- Multiple critical vulnerabilities in cPanel & WHM, including remote code execution (RCE) and stored Cross-Site Scripting (XSS), were disclosed on September 29, 2026.
- The most severe flaw, CVE-2026-93698, allows arbitrary command execution as the root user, leading to full server compromise.
- All supported versions of cPanel & WHM are affected prior to the latest patched releases.
- Immediate updates are required to mitigate the risk of server compromise and data exposure.
Critical Flaws in cPanel & WHM Expose Servers to Root-Level Attacks
Several significant security vulnerabilities within the cPanel & WHM web hosting automation platform have been publicly disclosed, potentially allowing attackers to execute arbitrary commands as the root user or inject malicious scripts into administrative browser sessions. These flaws, revealed on September 29, 2026, impact all supported cPanel & WHM versions that predate the vendor’s recently issued security updates.
Table Of Content
- Key Takeaways
- Critical Flaws in cPanel & WHM Expose Servers to Root-Level Attacks
- Deep Dive into the Vulnerabilities
- CVE-2026-93698: Arbitrary Command Execution
- CVE-2026-93029: Stored XSS in Manage SSL Hosts
- CVE-2026-93697: Stored XSS in Account Modification Interfaces
- Patch Availability and Urgency
- What You Should Do
The most severe of these issues, CVE-2026-93698, resides in the Multilang adminbin component. A successful exploit of this vulnerability could lead to a complete compromise of the affected server, granting attackers root-level access. Such access would jeopardize every hosted account, website, database, and service residing on the compromised machine.
Deep Dive into the Vulnerabilities
The disclosed vulnerabilities encompass both command execution and stored Cross-Site Scripting (XSS) weaknesses, each posing distinct risks to cPanel & WHM environments.
CVE-2026-93698: Arbitrary Command Execution
The most critical vulnerability, CVE-2026-93698, stems from insufficient validation within the Multilang adminbin component. According to cPanel’s official advisory, this flaw enables arbitrary command execution, ultimately allowing an attacker to execute code with root privileges.
Gaining root access in shared hosting or managed server environments is catastrophic. An attacker can then access, modify, or delete data across all customer accounts, deploy persistent malware, create unauthorized administrative users, steal sensitive credentials, disable security mechanisms, and alter critical server configurations. Unlike the XSS vulnerabilities, which depend on an administrator viewing malicious content, the Multilang adminbin flaw directly facilitates command execution, making it an urgent patching priority for all system administrators.
CVE-2026-93029: Stored XSS in Manage SSL Hosts
Another significant vulnerability, CVE-2026-93029, is a stored Cross-Site Scripting (XSS) flaw found in the WHM Manage SSL Hosts interface. An attacker, even with unprivileged account access, could inject and store malicious script content. This script would then execute within a WHM administrator’s browser session when they subsequently view the compromised interface.
Because the script runs within the context of an authenticated administrator’s session, an attacker could potentially hijack the session to perform actions with the administrator’s full permissions. This includes the ability to modify server settings, manage user accounts, or alter SSL-related configurations without direct authentication.
CVE-2026-93697: Stored XSS in Account Modification Interfaces
A second stored XSS vulnerability, identified as CVE-2026-93697, affects the WHM Mass Modify Accounts interface. Similar to the SSL hosts vulnerability, exploiting this flaw requires an attacker to store malicious content that is later accessed by a WHM administrator. Upon viewing the affected interface, the malicious code executes within the administrator’s session, potentially enabling the attacker to perform administrative actions on behalf of the legitimate user.
Patch Availability and Urgency
At the time of this report, no public proof-of-concept exploit code for these vulnerabilities has been identified. However, the detailed technical advisories increase the likelihood of attackers developing exploits, especially against unpatched, internet-facing WHM interfaces. All supported cPanel & WHM versions are vulnerable until upgraded to specific patched releases: 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11, or WP2 11.138.1.13, or any later versions. These same patch levels address all three identified CVEs.
What You Should Do
- Update Immediately: Administrators must update their cPanel & WHM installations to the latest available patched releases (11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11, WP2 11.138.1.13, or newer) without delay.
- Review Logs and Activity: Conduct a thorough review of WHM administrator activity, account changes, authentication logs, newly created privileged users, cron jobs, and any unexpected modifications to server or hosting-account settings.
- Restrict WHM Access: Implement strict access controls for WHM. This includes using firewall rules, VPN access, IP allowlists, and mandating multi-factor authentication for all administrative accounts.
- Audit Account Privileges: Hosting providers should review the privileges assigned to lower-level account holders and investigate any suspicious input submitted through SSL host management, account modification, or Multilang-related functions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.