Cyber Security News

Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking

cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM administrator sessions or execute commands as the root user.

Organizations using affected deployments should prioritize upgrades, as these flaws affect all supported versions of cPanel & WHM before the newly released fixed versions.

cPanel & WHM Vulnerabilities

The most critical issue, identified as CVE-2026-93698, affects the Multilang adminbin component. This vulnerability arises from insufficient input validation, permitting arbitrary command execution through the component.

According to cPanel’s advisory, successful exploitation can enable an attacker to execute code as the root user, the highest-privileged account on a Linux server.

This access could grant an attacker complete control over the server, including hosted customer accounts, websites, application files, email data, databases, and server configurations.

Publicly indexed information assigns CVE-2026-93698 a CVSS v3 base score of 9.9, classifying it as critical. This score reflects a network-accessible, low-complexity attack path with severe impacts on confidentiality, integrity, and availability.

However, defenders should distinguish the impact statement from exploit conditions: cPanel’s published advisory states arbitrary commands can be executed through Multilang adminbin, while third-party listings may vary in their interpretation of prerequisites.

Therefore, administrators should treat the vendor’s update guidance as the authoritative source for remediation.

The other two vulnerabilities, CVE-2026-93029 and CVE-2026-93697, are stored cross-site scripting (XSS) vulnerabilities located in WHM administrative interfaces.

CVE-2026-93029 affects the Manage SSL Hosts interface, while CVE-2026-93697 impacts the Mass Modify Accounts interface. Both flaws allow an unprivileged account holder to store malicious script content that executes when an administrator later accesses the affected interface.

This execution occurs within the security context of the administrator’s authenticated WHM session. As a result, an attacker could potentially perform administrative actions accessible to that administrator, posing a significant session-hijacking risk in shared hosting and multi-tenant server environments.

Potential consequences include modifying hosting account settings, changing SSL configurations, creating or altering accounts, and using the administrator’s privileges to establish further persistence. Do not dismiss the XSS issues as minor browser-side bugs, as they directly target a highly privileged management plane.

cPanel has issued fixes for all three vulnerabilities in cPanel & WHM versions 11.110.0.148, 11.134.0.61, 11.136.0.45, and 11.138.0.11 or later. Users of WP Squared should update to version 11.138.1.13 or later. The advisories were published on September 29, 2026.

Administrators should promptly update affected servers to the latest available patched version, not just the minimum fixed version. They should also review WHM access logs, privileged session activity, account modifications, SSL host changes, and any unexpected command executions for signs of post-exploitation activity.

Restricting WHM administrative access to trusted IP addresses, enforcing multi-factor authentication, and reducing the number of privileged WHM users can help limit exposure while updates are being deployed.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago