Security: CVE-2026-93029 Stored XSS in WHM’s Manage SSL Hosts Interface – September 29, 2026
CVE-2026-93029 is a stored XSS vulnerability in the WHM Manage SSL Hosts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can execute script in a WHM administrator's session context, so update cPanel/WHM to a patched release.
SharedLicense लाइसेंस के तहत इसका अर्थ
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator's session, which can be used to perform administrative actions as that user.
Situation
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
अक्सर पूछे जाने वाले प्रश्न
What is CVE-2026-93029?
Which cPanel/WHM versions are affected and which are patched?
How do I fix CVE-2026-93029?
Is CVE-2026-93029 being exploited in the wild?
अपने सिस्टम में भेद्यताओं की जाँच करें
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
अपना सिस्टम जाँचें