Back to Security Advisories

WHMCS 9.0.4 Security Update

Client Area Authorization Bypass (CVE-2026-29204)

Critical 9.1 CVSS
WHMCS

Default Update CMD

Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a vulnerability in WHMCS software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell WHMCS under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

9.0.4 (Maintenance) Security Fixes

WHMCS 9.0.4 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.

Client Area Authorization Bypass (CVE-2026-29204)

CVE-2026-29204 is an authorization bypass (an Insecure Direct Object Reference, CWE-639) in the Client Area. clientarea.php fails to verify that an addonId submitted in a request actually belongs to the logged-in user. As a result, an authenticated client can submit requests using another user’s addon ID and act in the context of the victim’s account, including accessing services and cPanel resources they do not own.

The flaw affects WHMCS 7.4.0 and later, and is fixed in 8.13.3 (8.x) and 9.0.4 (9.x). It scores 9.1 (Critical) on CVSS 3.1. Exploitation requires a valid, authenticated session, but any registered client account is enough, and the barrier to obtaining one is effectively zero. If you cannot update immediately, block requests to clientarea.php that carry an addonId parameter as a stopgap.

Affected Versions and Remediation

Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.

Frequently Asked Questions

What is CVE-2026-29204?
Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.
Is CVE-2026-29204 being exploited in the wild?
No confirmed exploitation has been announced. Patch on your normal schedule and watch the vendor advisory for updates.
How do I fix CVE-2026-29204?
Update WHMCS to the patched release.Then confirm the running version matches the patched release listed above.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System