CyberSecurity SEE

Multiple cPanel and WHM Vulnerabilities Allow Root Code Execution and Admin Session Hijacking

Multiple cPanel and WHM Vulnerabilities Allow Root Code Execution and Admin Session Hijacking

cPanel Issues Urgent Security Updates to Address Critical Vulnerabilities in WHM Systems

cPanel has recently announced the release of critical security updates aimed at addressing three vulnerabilities in cPanel & WHM that have the potential to allow malicious actors to hijack WHM administrator sessions or execute commands as the root user. This announcement signals a pressing need for organizations utilizing cPanel & WHM to immediately upgrade their systems, as the identified flaws pose significant risks to all supported versions prior to the availability of fixed updates.

Overview of the Vulnerabilities

Among the three vulnerabilities, one stands out as particularly severe—designated as CVE-2026-93698. This flaw affects the Multilang adminbin component and arises from inadequate input validation. As a result, it permits arbitrary command execution through the compromised component. According to the advisory published by cPanel, successful exploitation of this vulnerability could lead an attacker to execute code with root privileges, granting them complete authority over the Linux server. Such access could compromise an array of sensitive data, including customer accounts, websites, application files, email information, databases, and essential server configurations.

The critical nature of this flaw is underscored by its Comprehensive Vulnerability Scoring System (CVSS) rating, which has been assigned a base score of 9.9. This rating indicates a notably high risk, reflecting a network-accessible attack vector that is low in complexity yet can have devastating impacts on aspects of confidentiality, integrity, and availability of the affected systems.

It’s crucial for defenders to accurately interpret the advisory provided by cPanel, which clearly states that arbitrary commands can be executed via the Multilang adminbin. However, interpretations of prerequisites and potential impacts may vary across third-party listings. Hence, system administrators should regard the vendor’s advisories as the definitive source for remediation.

Additional Vulnerabilities

Beyond CVE-2026-93698, cPanel also identified two additional vulnerabilities categorized as stored Cross-Site Scripting (XSS) flaws, designated as CVE-2026-93029 and CVE-2026-93697. Both vulnerabilities are located within the administrative interfaces of WHM. The first, CVE-2026-93029, affects the Manage SSL Hosts interface, while the second, CVE-2026-93697, impacts the Mass Modify Accounts interface.

These vulnerabilities enable unprivileged users to store malicious script content that can be triggered when an administrator accesses one of the affected interfaces. The execution of such scripts occurs within the security context of an authenticated WHM session, which poses a considerable risk of session hijacking in environments where multiple tenants share a server. The potential for an attacker to exploit this vulnerability includes altering hosting account settings, modifying SSL configurations, and using an administrator’s privileges to create or modify accounts, thereby escalating their access even further.

Significance and Remediation Steps

The implications of these vulnerabilities stress the need for immediate action from organizations using cPanel & WHM. cPanel has issued patches for all three vulnerabilities in multiple updated versions, including 11.110.0.148, 11.134.0.61, 11.136.0.45, and 11.138.0.11 or later. Users are advised to upgrade to version 11.138.1.13 or later specifically for WP Squared deployments. The advisories were released on September 29, 2026, and prompt action is crucial.

Administrators are encouraged to not only update affected servers to the latest available patched versions but also to exercise diligence in reviewing WHM access logs, monitoring privileged session activities, and examining any unexpected command executions. These steps are fundamental to detecting any signs of post-exploitation activity.

In addition to immediate upgrades, best practices such as restricting WHM administrative access to trusted IP addresses, enforcing multi-factor authentication, and limiting the number of privileged WHM users can significantly mitigate exposure risks while patches are being deployed.

The vulnerabilities discovered in cPanel & WHM illustrate the ongoing challenges organizations face in maintaining the security of their systems. By prioritizing timely updates and employing robust security practices, administrators can play a pivotal role in safeguarding sensitive data and maintaining system integrity.

Source link

Exit mobile version