Security: CVE-2026-93697 Stored XSS in WHM’s Account Modification Interfaces – September 29, 2026
CVE-2026-93697 is a stored XSS vulnerability in the WHM Mass Modify Accounts interface that allows arbitrary code execution, disclosed by cPanel on September 29, 2026. An unprivileged account holder can run script inside a WHM administrator's session, so update cPanel/WHM to a patched release promptly.
Что это значит по лицензии SharedLicense
Successful exploitation lets an unprivileged account holder execute script in the context of a WHM administrator's session and perform administrative actions as that user.
Situation
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation allows an unprivileged account holder to execute script in the context of a WHM administrator’s session, which can be used to perform administrative actions as that user.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Часто задаваемые вопросы
What is CVE-2026-93697?
Which cPanel/WHM versions are affected and which are patched?
How do I fix CVE-2026-93697?
Is CVE-2026-93697 being exploited in the wild?
Источники
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему