WHMCS 9.0.4 Security Update
Client Area Authorization Bypass (CVE-2026-29204)
Default Update CMD
Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).
9.0.4 (Maintenance) Security Fixes
WHMCS 9.0.4 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.
Client Area Authorization Bypass (CVE-2026-29204)
CVE-2026-29204 is an authorization bypass (an Insecure Direct Object Reference, CWE-639) in the Client Area. clientarea.php fails to verify that an addonId submitted in a request actually belongs to the logged-in user. As a result, an authenticated client can submit requests using another user’s addon ID and act in the context of the victim’s account, including accessing services and cPanel resources they do not own.
The flaw affects WHMCS 7.4.0 and later, and is fixed in 8.13.3 (8.x) and 9.0.4 (9.x). It scores 9.1 (Critical) on CVSS 3.1. Exploitation requires a valid, authenticated session, but any registered client account is enough, and the barrier to obtaining one is effectively zero. If you cannot update immediately, block requests to clientarea.php that carry an addonId parameter as a stopgap.
Affected Versions and Remediation
Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.
How to Apply the Fix
Update WHMCS to the latest patch release of your branch, then confirm the version in Help > About WHMCS.
Utilities → Update WHMCS (in the Admin Area)
References
Check your system for vulnerabilities
Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.
Check Your System