TL;DR
cPanel published security advisories addressing three critical cPanel security vulnerabilities across supported server platforms. Specifically, these flaws permit stored cross-site scripting attacks and root-level command execution. Therefore, hosting providers must upgrade to the latest cPanel and WHM maintenance releases immediately.
Turn matching CVEs into GitHub Issues automatically — no copy-pasting, no duplicates.
Try Team free for 14 daysWhy It Matters
cPanel and WHM power more than one million web servers globally, according to web hosting industry estimates. Consequently, unpatched cPanel security vulnerabilities expose thousands of shared hosting environments to severe threats. An unprivileged tenant could hijack administrator sessions or seize complete control of the host machine. Furthermore, full root compromise threatens every hosted website, user account, and database stored on that server. Hosting providers must prioritize these updates to protect client data and ensure system integrity.
How The Attack Works
The vulnerabilities exploit distinct flaws in input validation and administrative binary execution. First, an unprivileged user injects malicious JavaScript into the Manage SSL Hosts interface via CVE-2026-93029. When a WHM administrator views the stored content, the browser executes the script in the admin context. Similarly, CVE-2026-93697 allows attackers to store scripts within the WHM account modification interface. Most critically, CVE-2026-93698 involves insufficient input validation within the Multilang adminbin binary. Because of this flaw, attackers can execute arbitrary shell commands directly as the root superuser.
Exploitation Status
cPanel has not confirmed any active exploitation of these security flaws in the wild. In addition, researchers have not published any public proof-of-concept exploits for these issues.
Affected Versions
These vulnerabilities affect all supported versions of cPanel and WHM across production release tiers.
Patch And Mitigation Steps
Administrators must apply the latest cPanel updates to secure their hosting systems. Specifically, patched releases include versions 11.110.0.148, 11.134.0.61, 11.136.0.45, and 11.138.0.11 or later builds. Servers running WP Squared should update to build 11.138.1.13 or newer. You can trigger automatic updates directly through WHM or by running the standard cPanel update script via SSH.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!