Panellicense

cPanel TSR-2026-09-29: patch three WHM security vulnerabilities

cPanel TSR-2026-09-29 fixes two stored XSS flaws in WHM and a Multilang Adminbin authorization bypass that may permit command execution. Check your full build number and update now.

cPAll cPanel articlesNews & changelogs5 min readUpdated 2026-09-30
schema: TechArticleschema: FAQPageschema: BreadcrumbList

cPanel published TSR-2026-09-29 on 29 September 2026 to address three vulnerabilities in cPanel & WHM: two stored cross-site scripting flaws in WHM and an authorization bypass in the Multilang Adminbin component. cPanel lists all supported versions as affected and provides patched builds for branches 110, 134, 136, 138, and WP Squared 138.1.

The most consequential issue is CVE-2026-93698. cPanel says insufficient validation in Multilang Adminbin could allow unauthorized users to execute various commands on the server. The public advisory does not specify the command context, the privileges obtained, or whether active exploitation has been observed, so operators should not assume network restrictions or limited WHM access are sufficient mitigations.

Vulnerabilities fixed by TSR-2026-09-29

CVE-2026-93029: Manage SSL Hosts stored XSS

A stored cross-site scripting vulnerability affects WHM's Manage SSL Hosts interface. Malicious input saved through the affected workflow could execute JavaScript when a WHM operator later views the stored content. In an administrative browser session, stored XSS may expose sensitive page data or allow actions with the privileges available to that session.

CVE-2026-93697: Mass Modify Accounts stored XSS

A second stored XSS vulnerability affects WHM's Mass Modify Accounts interface. It is distinct from CVE-2026-93029 but has the same fixed-build boundaries. Servers that do not use Mass Modify Accounts still need the update because the TSR also repairs the other two vulnerabilities.

CVE-2026-93698: Multilang Adminbin authorization bypass

Insufficient validation in the Multilang Adminbin component may allow unauthorized users to execute various commands on the server. cPanel's public notice does not describe the required access level or claim that the resulting commands execute as root; avoid relying on assumptions about either point. Apply the vendor patch instead of treating access controls as a substitute.

Affected and patched builds

All supported cPanel & WHM versions are affected. Update to at least the first patched build for your branch:

cPanel & WHM branchFirst patched build
11.11011.110.0.142
11.13411.134.0.58
11.13611.136.0.40
11.13811.138.0.11
WP Squared 11.138.111.138.1.16

A later build in the same supported branch also contains these fixes. An end-of-life branch is not protected by enabling automatic updates; move it to a supported release first.

Check your installed version and update policy

Run these commands as root:

/usr/local/cpanel/cpanel -V
grep -E '^(CPANEL|UPDATES)=' /etc/cpupdate.conf

The first command prints the complete installed build. The second shows the selected release tier and whether normal updates are enabled.

If the server is pinned to an old or unsupported version, remove the pin before updating. The safest method is WHM > Server Configuration > Update Preferences: select a supported release tier and enable automatic updates. Do not blindly replace /etc/cpupdate.conf on a production server, because it may contain site-specific update settings you need to preserve.

Install the security update

Run cPanel's updater in force mode. According to cPanel's update documentation, this performs an update regardless of the normal update settings:

/usr/local/cpanel/scripts/upcp --force

After the update finishes, check the version again and inspect the latest update log:

/usr/local/cpanel/cpanel -V
tail -n 100 /var/cpanel/updatelogs/last

Confirm that the full version is equal to or newer than the fixed build in the table and that the update log does not end with a blocker or fatal error. If upcp fails, follow our cPanel update failure troubleshooting guide before assuming the server is protected.

What to do after patching

The update repairs the vulnerable code but cannot reverse activity that happened beforehand. For servers exposed while running an affected build:

  • review cPanel and system logs for unexpected WHM actions and command execution;
  • check for unfamiliar administrator or reseller accounts, SSH keys, cron jobs, and services;
  • review recently modified privileged files and unexplained outbound connections;
  • rotate privileged credentials from a trusted device if you find evidence of compromise;
  • isolate and investigate a suspected compromised server before returning it to production.

These are general incident-response precautions, not an indication from cPanel that exploitation has been observed.

Official references

Which cPanel versions are affected by TSR-2026-09-29?+
cPanel lists all supported versions as affected. Its advisory names fixed builds 11.110.0.142, 11.134.0.58, 11.136.0.40, 11.138.0.11, and WP Squared 11.138.1.16. The advisory does not list a branch 126 fixed build, so operators on 11.126 should move to a listed patched branch or obtain confirmation from cPanel Support.
How do I check whether my server is patched?+
Run /usr/local/cpanel/cpanel -V as root and compare the complete output with the first patched build for your branch. Checking only the major branch number is not sufficient.
How do I install the cPanel TSR-2026-09-29 update?+
Remove any pin that prevents the server from reaching a supported patched build, then run /usr/local/cpanel/scripts/upcp --force as root. Recheck the full version and the latest upcp log afterward.
Does CVE-2026-93698 provide root access?+
cPanel states that the authorization bypass may allow unauthorized users to execute various commands, but its public advisory does not specify the execution context or claim that commands run as root. Patch immediately without assuming a lower privilege level makes the issue safe.
Has cPanel reported active exploitation?+
The public TSR and CVE pages do not state whether exploitation has been observed. Absence of that statement is not evidence that exploitation has or has not occurred.

Next steps

changelog
cPanel TSR-2026-09-08: prepare for the critical WHM patch
cPanel pre-announced a Targeted Security Release for 8 September 2026 fixing a critical cPanel & WHM vulnerability. Here is how to identify affected servers and apply the fix.
4 min read
changelog
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
7 min read
changelog
CVE-2026-65643: patch the cPanel domain parking root vulnerability
CVE-2026-65643 lets an authenticated cPanel user with parked or addon-domain access create arbitrary server files and potentially execute code as root. Check the fixed builds and update now.
3 min read
changelog
CVE-2026-67401: the cPanel EmailTrack flaw that turns mail access into root
A SQL injection in cPanel's EmailTrack feature lets any account with mail privileges write files as root. Fixed builds, affected versions, and how to check your fleet.
7 min read
changelog
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
7 min read
changelog
EasyApache 4 25.82: cPanel patches ea-libxml2, ea-nginx, ea-ruby27-ruby
EasyApache 4 build 25.82 patches eight libxml2 CVEs, two Ruby resolv CVEs, and bumps ea-nginx to 1.31.5. Here's what's affected and how to update.
5 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.