cPanel published TSR-2026-09-29 on 29 September 2026 to address three vulnerabilities in cPanel & WHM: two stored cross-site scripting flaws in WHM and an authorization bypass in the Multilang Adminbin component. cPanel lists all supported versions as affected and provides patched builds for branches 110, 134, 136, 138, and WP Squared 138.1.
The most consequential issue is CVE-2026-93698. cPanel says insufficient validation in Multilang Adminbin could allow unauthorized users to execute various commands on the server. The public advisory does not specify the command context, the privileges obtained, or whether active exploitation has been observed, so operators should not assume network restrictions or limited WHM access are sufficient mitigations.
Vulnerabilities fixed by TSR-2026-09-29
CVE-2026-93029: Manage SSL Hosts stored XSS
A stored cross-site scripting vulnerability affects WHM's Manage SSL Hosts interface. Malicious input saved through the affected workflow could execute JavaScript when a WHM operator later views the stored content. In an administrative browser session, stored XSS may expose sensitive page data or allow actions with the privileges available to that session.
CVE-2026-93697: Mass Modify Accounts stored XSS
A second stored XSS vulnerability affects WHM's Mass Modify Accounts interface. It is distinct from CVE-2026-93029 but has the same fixed-build boundaries. Servers that do not use Mass Modify Accounts still need the update because the TSR also repairs the other two vulnerabilities.
CVE-2026-93698: Multilang Adminbin authorization bypass
Insufficient validation in the Multilang Adminbin component may allow unauthorized users to execute various commands on the server. cPanel's public notice does not describe the required access level or claim that the resulting commands execute as root; avoid relying on assumptions about either point. Apply the vendor patch instead of treating access controls as a substitute.
Affected and patched builds
All supported cPanel & WHM versions are affected. Update to at least the first patched build for your branch:
| cPanel & WHM branch | First patched build |
|---|---|
| 11.110 | 11.110.0.142 |
| 11.134 | 11.134.0.58 |
| 11.136 | 11.136.0.40 |
| 11.138 | 11.138.0.11 |
| WP Squared 11.138.1 | 11.138.1.16 |
A later build in the same supported branch also contains these fixes. An end-of-life branch is not protected by enabling automatic updates; move it to a supported release first.
Check your installed version and update policy
Run these commands as root:
/usr/local/cpanel/cpanel -V
grep -E '^(CPANEL|UPDATES)=' /etc/cpupdate.conf
The first command prints the complete installed build. The second shows the selected release tier and whether normal updates are enabled.
If the server is pinned to an old or unsupported version, remove the pin before updating. The safest method is WHM > Server Configuration > Update Preferences: select a supported release tier and enable automatic updates. Do not blindly replace /etc/cpupdate.conf on a production server, because it may contain site-specific update settings you need to preserve.
Install the security update
Run cPanel's updater in force mode. According to cPanel's update documentation, this performs an update regardless of the normal update settings:
/usr/local/cpanel/scripts/upcp --force
After the update finishes, check the version again and inspect the latest update log:
/usr/local/cpanel/cpanel -V
tail -n 100 /var/cpanel/updatelogs/last
Confirm that the full version is equal to or newer than the fixed build in the table and that the update log does not end with a blocker or fatal error. If upcp fails, follow our cPanel update failure troubleshooting guide before assuming the server is protected.
What to do after patching
The update repairs the vulnerable code but cannot reverse activity that happened beforehand. For servers exposed while running an affected build:
- review cPanel and system logs for unexpected WHM actions and command execution;
- check for unfamiliar administrator or reseller accounts, SSH keys, cron jobs, and services;
- review recently modified privileged files and unexplained outbound connections;
- rotate privileged credentials from a trusted device if you find evidence of compromise;
- isolate and investigate a suspected compromised server before returning it to production.
These are general incident-response precautions, not an indication from cPanel that exploitation has been observed.
Official references
- cPanel TSR-2026-09-29 security release
- CVE-2026-93029: Manage SSL Hosts Stored XSS
- CVE-2026-93697: Mass Modify Accounts Stored XSS
- CVE-2026-93698: Multilang Adminbin Authorization Bypass
- cPanel update documentation
Which cPanel versions are affected by TSR-2026-09-29?+
How do I check whether my server is patched?+
How do I install the cPanel TSR-2026-09-29 update?+
Does CVE-2026-93698 provide root access?+
Has cPanel reported active exploitation?+
Next steps
- Fix cPanel update failures in upcp
- cPanel update tiers explained
- CVE-2026-65643: patch the cPanel domain parking root vulnerability
- Keep an active cPanel license so supported servers can receive security updates.