securityonline.info 16 Sept 2026, 00:00 UTC

WHMCS Fixes Critical Flaw Allowing Unauthenticated Code Execution

WHMCS Fixes Critical Flaw Allowing Unauthenticated Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

WHMCS released maintenance updates on 3 September 2026 to address two vulnerabilities affecting its web-hosting billing and provisioning platform. CVE-2026-67399 is rated critical, with a CVSS v4 score of 9.3, and involves forged payloads being submitted without adequate restrictions. According to the cited advisory, an unauthenticated attacker could send crafted network requests and execute arbitrary code on the host server. The flaw affects WHMCS 8.0.x and later.

CVE-2026-67398, rated 8.2, affects the 2CheckOut payment gateway module. An unauthenticated user could query the payment handler to retrieve client personally identifiable information, including names, addresses, email addresses and telephone numbers. The report says there is no confirmed exploitation in the wild and no publicly available proof-of-concept code.

WHMCS administrators should update to version 9.0.8 or 8.13.7; CVE-2026-67398 is also fixed in 8.12.2. The report states that 9.x installations before 9.0.8 and 8.x installations before 8.13.7 are affected. Where an immediate update is not possible, administrators are advised to disable the 2CheckOut payment module in the payment gateway settings.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline