सुरक्षा सलाह पर वापस जाएँ

Security: CVE-2026-93029 Stored XSS in WHM’s Manage SSL Hosts Interface – September 29, 2026

CVE-2026-93029 is a stored XSS vulnerability in the WHM Manage SSL Hosts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can execute script in a WHM administrator's session context, so update cPanel/WHM to a patched release.

Critical 9 CVSS
cPanel

SharedLicense लाइसेंस के तहत इसका अर्थ

Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator's session, which can be used to perform administrative actions as that user.

Situation

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • 11.110.0.148 or later
  • 11.134.0.61 or later
  • 11.136.0.45 or later
  • 11.138.0.11 or later
  • WP2: 11.138.1.13 or later

Impact

Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

अक्सर पूछे जाने वाले प्रश्न

What is CVE-2026-93029?
It is the CVE ID cPanel assigned to a stored XSS vulnerability in the WHM Manage SSL Hosts interface, published September 29, 2026. All supported cPanel/WHM versions are affected. cPanel has not published a CVSS score for it yet.
Which cPanel/WHM versions are affected and which are patched?
All supported cPanel/WHM versions are affected. Patched versions are 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11 or later — the fix spans the 11.110, 11.134, 11.136 and 11.138 release tiers, plus WP2 11.138.1.13.
How do I fix CVE-2026-93029?
Update cPanel/WHM: run sudo /scripts/upcp --force. The patched builds are 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11 or later (WP2: 11.138.1.13 or later).
Is CVE-2026-93029 being exploited in the wild?
cPanel's advisory does not report any active exploitation, and no CVSS score has been published yet. Because the impact ranges from admin-session takeover to root code execution, treat the update as urgent.

अपने सिस्टम में भेद्यताओं की जाँच करें

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

अपना सिस्टम जाँचें