Security: CVE-2026-93698 Vulnerability in Multilang Adminbin – September 29, 2026
CVE-2026-93698 is insufficient validation in the cPanel/WHM Multilang adminbin that allows arbitrary command execution — disclosed by cPanel on September 29, 2026, and the most severe of the three advisories published that day. Successful exploitation leads to code execution as the root user, so update cPanel/WHM to a patched release immediately.
What this means under a SharedLicense license
Successful exploitation leads to code execution as the root user — full control of the server and every account, website, and database on it.
Situation
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Frequently Asked Questions
What is CVE-2026-93698?
Which cPanel/WHM versions are affected and which are patched?
How do I fix CVE-2026-93698?
Is CVE-2026-93698 being exploited in the wild?
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System