Security: CVE-2026-93029 Stored XSS in WHM’s Manage SSL Hosts Interface – September 29, 2026
CVE-2026-93029 is a stored XSS vulnerability in the WHM Manage SSL Hosts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can execute script in a WHM administrator's session context, so update cPanel/WHM to a patched release.
What this means under a SharedLicense license
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator's session, which can be used to perform administrative actions as that user.
Situation
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Frequently Asked Questions
What is CVE-2026-93029?
Which cPanel/WHM versions are affected and which are patched?
How do I fix CVE-2026-93029?
Is CVE-2026-93029 being exploited in the wild?
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System