cPanel Fixes Root Execution and Two WHM Stored-XSS Flaws
cPanel has fixed three vulnerabilities affecting every supported cPanel and WHM release. One reaches root; two are stored-XSS flaws in WHM. The 29 September advisories do not say whether any flaw has been exploited.
The Multilang path reaches root
CVE-2026-93698 is an insufficient-validation flaw in the Multilang adminbin that can permit arbitrary commands. Successful exploitation runs code as root and gives full server control. The public page does not state the prerequisite, so it is not evidence of an unauthenticated attack.
The WHM flaws inherit an administrator’s session
CVE-2026-93697 affects Mass Modify Accounts. An unprivileged account holder can store script that runs in a WHM administrator’s session and performs actions as that user.
CVE-2026-93029 creates the same risk through Manage SSL Hosts. These advisories describe browser script with WHM authority, not operating-system commands running as root.
Verify the complete build
All supported versions are affected.
| Product line | Minimum patched build |
|---|---|
| cPanel and WHM 110 | 11.110.0.148 |
| cPanel and WHM 134 | 11.134.0.61 |
| cPanel and WHM 136 | 11.136.0.45 |
| cPanel and WHM 138 | 11.138.0.11 |
| WP Squared 138 | 11.138.1.13 |
cPanel directs customers to the latest patched version. Verify the full installed build on each server rather than relying on the major release number.
This is not the earlier EmailTrack flaw
BlackTree’s earlier cPanel report covered a different EmailTrack path with a mail-related account prerequisite and older fixed builds.
Sources
- Multilang adminbin advisory for CVE-2026-93698, displayed 29 September 2026 at 16:41; timezone not stated.
- Mass Modify Accounts advisory for CVE-2026-93697, displayed 29 September 2026 at 16:53; timezone not stated.
- Manage SSL Hosts advisory for CVE-2026-93029, displayed 29 September 2026 at 16:47; timezone not stated.


