# Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code Execution and Admin Session Hijacking

> cPanel patched three vulnerabilities in cPanel & WHM on 2026-09-29: CVE-2026-93698, an OS command injection in the Multilang adminbin that permits code execution as root (CVSS 9.9), and two stored XSS flaws in WHM's Manage SSL Hosts (CVE-2026-93029) and Mass Modify Accounts (CVE-2026-93697) interfaces that allow script execution in administrator sessions. No in-the-wild exploitation or public PoC is reported.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2912
- **ID:** TL-2026-2912
- **Severity:** CRITICAL (CVSS 9.9)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-93698, CVE-2026-93029, CVE-2026-93697

## Description

On 2026-09-29 cPanel published three security advisories and fixed builds for cPanel & WHM and WP Squared. The fixes ship in cPanel & WHM 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11, and in WP Squared 11.138.1.13. All supported versions before those builds are affected. NVD published the CVE records on 2026-10-02.

CVE-2026-93698 is an insufficient-validation flaw (CWE-78) in the Multilang adminbin, the privileged helper through which cPanel account-level callers reach root-run functionality. Per the NVD record it allows arbitrary commands to be executed via that adminbin. The CVSS 3.0 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (9.9): it is network-reachable, needs only low privileges (an authenticated cPanel account) and no user interaction, and scope changes. Trade press describes the impact as code execution as root, the highest-privileged account on the Linux server, so a low-privileged hosted account could take over the whole host and every other tenant on it. The same component had earlier root-execution and feature-list-bypass issues (CVE-2017-18434 via SET_VHOST_LANG_PACKAGE, CVE-2016-10772), so it is a recurring hardening target.

CVE-2026-93029 (WHM Manage SSL Hosts interface) and CVE-2026-93697 (WHM Mass Modify Accounts / account modification interfaces) are stored cross-site scripting flaws (CWE-79). An unprivileged or low-privileged user can store script that runs when an administrator views the page, so the attacker can perform any administrative action available to that administrator, including session hijacking. NVD scores both 9.0 (CVSS 3.0 AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H); the vendor and press describe them as moderate, so scoring differs between sources.

The source reports no evidence of active exploitation, no public PoC, no IOCs and no named threat actor. Context for prioritization: cPanel was heavily targeted earlier in 2026. CVE-2026-41940, an authentication bypass, was reported exploited as a zero-day, with Mirai and the Sorry ransomware deployed. Three further cPanel flaws (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) were patched in May 2026 with no exploitation reported. This is unrelated to the present flaws but shows attacker interest in the platform. Defenders should treat this as a patch-priority advisory for all internet-exposed WHM/cPanel hosts and shared-hosting providers.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1539 Steal Web Session Cookie

## Sources

- [cPanel Security: CVE-2026-93698 Vulnerability in Multilang Adminbin (September 29, 2026)](https://support.cpanel.net/hc/en-us/articles/43845931719447-Security-CVE-2026-93698-Vulnerability-in-Multilang-Adminbin-September-29-2026)
- [cPanel Security: CVE-2026-93029 Stored XSS in WHM's Manage SSL Hosts Interface (September 29, 2026)](https://support.cpanel.net/hc/en-us/articles/43845929235351-Security-CVE-2026-93029-Stored-XSS-in-WHM-s-Manage-SSL-Hosts-Interface-September-29-2026)
- [cPanel Security: CVE-2026-93697 Stored XSS in WHM's Account Modification Interfaces (September 29, 2026)](https://support.cpanel.net/hc/en-us/articles/43845930445207-Security-CVE-2026-93697-Stored-XSS-in-WHM-s-Account-Modification-Interfaces-September-29-2026)
- [Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking (GBHackers)](https://gbhackers.com/multiple-cpanel-whm-vulnerabilities/)
- [NVD: CVE-2026-93698](https://nvd.nist.gov/vuln/detail/CVE-2026-93698)
- [NVD: CVE-2026-93029](https://nvd.nist.gov/vuln/detail/CVE-2026-93029)
- [NVD: CVE-2026-93697](https://nvd.nist.gov/vuln/detail/CVE-2026-93697)
- [HackerOne report 4054291 (CVE-2026-93698)](https://hackerone.com/reports/4054291)
- [HackerOne report 4047106 (CVE-2026-93029)](https://hackerone.com/reports/4047106)
- [HackerOne report 4047787 (CVE-2026-93697)](https://hackerone.com/reports/4047787)
- [cPanel & WHM 11.110 change log (build 11.110.0.148)](https://docs.cpanel.net/changelogs/110-change-log/#1100148)
- [cPanel, WHM patch 3 new vulnerabilities (The Hacker News, May 2026)](https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html)
- [Multiple threat actors actively exploit cPanel vulnerability (CVE-2026-41940) - Help Net Security](https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2912
