Zurück zu den Sicherheitshinweisen

Security: CVE-2026-93029 Stored XSS in WHM’s Manage SSL Hosts Interface – September 29, 2026

CVE-2026-93029 is a stored XSS vulnerability in the WHM Manage SSL Hosts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can execute script in a WHM administrator's session context, so update cPanel/WHM to a patched release.

Critical 9 CVSS
cPanel

Was das unter einer SharedLicense-Lizenz bedeutet

Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator's session, which can be used to perform administrative actions as that user.

Situation

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • 11.110.0.148 or later
  • 11.134.0.61 or later
  • 11.136.0.45 or later
  • 11.138.0.11 or later
  • WP2: 11.138.1.13 or later

Impact

Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Häufig gestellte Fragen

What is CVE-2026-93029?
It is the CVE ID cPanel assigned to a stored XSS vulnerability in the WHM Manage SSL Hosts interface, published September 29, 2026. All supported cPanel/WHM versions are affected. cPanel has not published a CVSS score for it yet.
Which cPanel/WHM versions are affected and which are patched?
All supported cPanel/WHM versions are affected. Patched versions are 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11 or later — the fix spans the 11.110, 11.134, 11.136 and 11.138 release tiers, plus WP2 11.138.1.13.
How do I fix CVE-2026-93029?
Update cPanel/WHM: run sudo /scripts/upcp --force. The patched builds are 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11 or later (WP2: 11.138.1.13 or later).
Is CVE-2026-93029 being exploited in the wild?
cPanel's advisory does not report any active exploitation, and no CVSS score has been published yet. Because the impact ranges from admin-session takeover to root code execution, treat the update as urgent.

System auf Schwachstellen prüfen

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

System prüfen