BlackTree Security · Infrastructure · Automation · AI

cPanel Fixes Root Execution and Two WHM Stored-XSS Flaws

cPanel has fixed three vulnerabilities affecting every supported cPanel and WHM release. One reaches root; two are stored-XSS flaws in WHM. The 29 September advisories do not say whether any flaw has been exploited.

The Multilang path reaches root

CVE-2026-93698 is an insufficient-validation flaw in the Multilang adminbin that can permit arbitrary commands. Successful exploitation runs code as root and gives full server control. The public page does not state the prerequisite, so it is not evidence of an unauthenticated attack.

The WHM flaws inherit an administrator’s session

CVE-2026-93697 affects Mass Modify Accounts. An unprivileged account holder can store script that runs in a WHM administrator’s session and performs actions as that user.

CVE-2026-93029 creates the same risk through Manage SSL Hosts. These advisories describe browser script with WHM authority, not operating-system commands running as root.

Verify the complete build

All supported versions are affected.

Product lineMinimum patched build
cPanel and WHM 11011.110.0.148
cPanel and WHM 13411.134.0.61
cPanel and WHM 13611.136.0.45
cPanel and WHM 13811.138.0.11
WP Squared 13811.138.1.13

cPanel directs customers to the latest patched version. Verify the full installed build on each server rather than relying on the major release number.

This is not the earlier EmailTrack flaw

BlackTree’s earlier cPanel report covered a different EmailTrack path with a mail-related account prerequisite and older fixed builds.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *