Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Multiple security flaws in cPanel & WHM could let attackers run malicious scripts in an administrator’s browser session or execute arbitrary commands as root. The vulnerabilities were disclosed on September 29, 2026, and affect all supported cPanel & WHM versions before the vendor’s patched releases.

Administrators should update immediately, as a successful attack against the command-execution flaw could expose every hosting account, website, database, and service hosted on an affected machine. The most severe issue, CVE-2026-93698, affects the Multilang adminbin component and can result in full server compromise.

CVE-2026-93029 is a stored cross-site scripting vulnerability in the WHM Manage SSL Hosts interface. An unprivileged account holder may be able to store malicious script content that executes when a WHM administrator later views the affected interface.

Because the script runs within the administrator’s authenticated browser session, an attacker could potentially perform actions with the same permissions available to that administrator. This may include modifying server settings, managing accounts, or changing SSL-related configurations.

A second stored XSS issue, tracked as CVE-2026-93697, affects the WHM Mass Modify Accounts interface. Like the Manage SSL Hosts vulnerability, exploitation requires storing malicious content and later opening it as a WHM administrator. The flaw allows code to execute in the administrator’s session context, enabling administrative actions on the targeted user’s behalf.

Multiple Cpanel/WHM Vulnerabilities

The most serious vulnerability is CVE-2026-93698, which is caused by insufficient validation in the Multilang adminbin component. According to cPanel’s advisory, this weakness allows arbitrary command execution. It can lead to code execution as the root user.

Root-level command execution presents a major risk in shared-hosting and managed-server environments. An attacker with root access can read or alter data across all hosted accounts, install persistent malware, create unauthorized users, steal credentials, turn off security tools, and modify server configurations.

Unlike the two XSS vulnerabilities, which rely on an administrator viewing malicious stored content, the Multilang adminbin flaw directly concerns command execution. Security teams should treat it as an urgent patching priority because compromise of the underlying server can affect every customer and workload running on the system.

No public proof-of-concept exploit code was identified in the available vulnerability-tracking information at the time of reporting. However, the availability of technical advisory details may increase attacker interest, particularly where internet-exposed WHM interfaces have not been updated.

All supported cPanel & WHM versions are affected until upgraded to 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11, or WP2 11.138.1.13, or later. The same patched version set applies to CVE-2026-93029, CVE-2026-93697, and CVE-2026-93698, based on the disclosed product-version information.

Administrators should update cPanel & WHM to the latest available patched release as soon as possible. Organizations should also review WHM administrator activity, account changes, authentication logs, newly created privileged users, cron jobs, and unexpected modifications to server or hosting-account settings.

Restrict WHM access through firewall rules, VPN access, IP allowlists, and multi-factor authentication. Hosting providers should also review the privileges granted to lower-level account holders and investigate suspicious input submitted through SSL-host management, account-modification, or Multilang-related functions.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Multiple Cpanel/WHM Vulnerabilities Allow Arbitrary Command Execution On Server appeared first on Cyber Security News.