WHMCS 8.13.7 Security Update
Unauthenticated Remote Code Execution (CVE-2026-67399)
डिफ़ॉल्ट अपडेट कमांड
Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).
SharedLicense लाइसेंस के तहत इसका अर्थ
Your SharedLicense license itself is not affected — this is a vulnerability in WHMCS software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell WHMCS under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.
8.13.7 (Maintenance Release) Security Fixes
WHMCS 8.13.7 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.
Unauthenticated Remote Code Execution (CVE-2026-67399)
This is the most serious issue in the release. CVE-2026-67399 is an unauthenticated remote code execution flaw. An attacker with no account can submit a forged payload that WHMCS processes without adequate restrictions, and under specific conditions this leads to arbitrary code execution on the server. The vulnerability has been present since WHMCS 8.0 and affects every build before 8.13.7 (8.x) or 9.0.8 (9.x).
The likely mechanism is insecure deserialization / PHP object injection: attacker-controlled data is turned back into live objects that WHMCS then trusts. Because it is reachable with no login and there is no customer-side workaround, the update is the only fix. An attacker who succeeds gains full control of the WHMCS host, including the billing database, client records, and payment details.
Customer Data Disclosure via 2Checkout Gateway (CVE-2026-67398)
CVE-2026-67398 is a missing authorization flaw in the 2Checkout payment gateway module. An unauthenticated user can hit the gateway endpoint and, under specific conditions, retrieve a customer’s personally identifiable information: name, mailing address, city, state, postal code, country, email, and phone number.
It only affects installations that run the 2Checkout module, and the affected range reaches back to WHMCS 4.5.0. The CVSS 4.0 score is 8.2 (High). Unlike the RCE, this one has an interim mitigation: deactivate the 2Checkout payment gateway module until you can update, then switch payments to an alternative gateway.
Affected Versions and Remediation
Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.
अक्सर पूछे जाने वाले प्रश्न
What is CVE-2026-67399?
Is CVE-2026-67399 being exploited in the wild?
How do I fix CVE-2026-67399?
Why does this advisory list several CVEs?
संदर्भ
अपने सिस्टम में भेद्यताओं की जाँच करें
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
अपना सिस्टम जाँचें