Back to Security Advisories
High 2026-03-21

Security Advisory: WHMCS Admin Password Reset Weak Token

WHMCS

Password reset tokens in WHMCS were generated with insufficient entropy, allowing brute-force recovery of the reset URL for administrator accounts.

Affected Versions

WHMCS 8.9.0 and earlier

Patched Version

WHMCS 8.10.1

Default Update CMD

yum update -y

Fix Commands

All Systems

Back up /var/www/html/whmcs
Download the patched release
Run the upgrade wizard at /install/upgrade
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System