securityonline.info 2 Oct 2026, 02:20 UTC

cPanel Fixes Flaws That Could Let Hackers Seize Servers as Root

cPanel Fixes Flaws That Could Let Hackers Seize Servers as Root
CyberSIXT Evidence Panel Source marked as original reporting

THREE cPanel/WHM security advisories detail critical flaws across supported server platforms, enabling stored cross-site scripting (XSS) alongside potential root-level command execution. The vulnerabilities are CVE-2026-93029 (stored XSS via the Manage SSL Hosts interface), CVE-2026-93697 (stored XSS in the WHM account modification interfaces), and CVE-2026-93698 (a flaw in input handling within the Multilang adminbin binary that could allow arbitrary shell commands to run as root).

The combined effect is that an unprivileged user could inject malicious scripts, which when viewed by a WHM administrator, run in the admin context, with the most severe impact being full root compromise of the host.

Exploitation status remains unconfirmed; no active in-the-wild exploitation or public PoCs have been published to date. The advisories state that all supported cPanel and WHM versions are affected, so timely patching is essential. Administrators should upgrade to the latest maintenance releases: 11.110.0[.]148, 11.134.0[.]61, 11.136.0[.]45, or 11.138.0[.]11 (or later builds). WP Squared deployments should move to 11.138.1[.]13 or newer.

Updates can be applied automatically via WHM or by running the standard cPanel update script over SSH. These steps are necessary to protect hosted sites, user accounts, and databases from compromise due to elevated privileges or complete server takeover. 2 October 2026

View full article

Article by CyberSIXT