CVE-2026-93698: cPanel Multilang Adminbin Command Execution
TL;DR - CVE-2026-93698 is a critical command execution flaw in cPanel’s Multilang Adminbin, rated CVSS 9.9. - Affected cPanel and WP Squared installations should be upgraded to the listed fixed builds. - CISA KEV does not list the CVE, and no credible public PoC or confirmed exploitation was identified in the available research.
Vulnerability at a Glance
CVE-2026-93698 affects cPanel & WHM and related WP Squared builds. The vulnerability involves insufficient validation in the Multilang Adminbin component and may allow arbitrary commands to execute on the server. Because cPanel commonly manages multiple websites, mailboxes, databases, and hosting accounts, compromise of the control-plane server can affect more than one application.
| Field | Details |
|---|---|
| CVE ID | CVE-2026-93698 |
| CVSS score | 9.9 |
| CVSS vector | Not present in the retrieved NVD record |
| Attack vector | Not specified in the retrieved NVD record |
| Authentication required | Not specified in the retrieved NVD record |
| Patch available | Yes |
| CISA KEV status | Not listed |
| Primary impact | Potential arbitrary command execution |
The 9.9 score indicates a critical issue, but the available record does not include the CVSS vector. Do not infer network reachability, authentication requirements, or privileges from the score alone. A supplemental advisory summary describes the issue as potentially exploitable by unauthorized users. Confirm that detail against the complete vendor advisory before treating it as definitive.
What Is This Vulnerability?
NVD describes CVE-2026-93698 as an issue where “insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.” The root cause is inadequate validation of input or command-related data handled by the Multilang Adminbin component. In practical terms, attacker-controlled values may reach a command execution path without sufficient filtering, validation, or safe handling.
The exact request format, vulnerable code path, and required authorization context are not available in the retrieved NVD response. Supplemental advisory information characterizes the issue as allowing unauthorized users to execute commands on the server, but the precise attack sequence remains unconfirmed from the available primary material. Defenders should still treat exposed affected systems as high risk because arbitrary command execution can enable account tampering, data theft, persistence, malware deployment, or access to other hosted tenants.
Technical Notes
The key distinction is between command injection or unsafe command construction and a conventional web application authorization flaw. If an attacker can cause the Adminbin to invoke operating-system commands, the resulting permissions depend on the process identity and cPanel security controls. A low-privilege execution context may still expose hosted content, credentials, scheduled tasks, configuration files, and local service tokens.
Restricting the public web server does not necessarily eliminate exposure. cPanel and WHM installations include administrative services and supporting components that may be reachable through management interfaces, local integrations, or authenticated control-panel workflows. The complete vendor advisory is needed to establish the exact preconditions.
Who Is Affected?
The available advisory information identifies supported cPanel & WHM release branches before the following fixed builds as affected:
| Product or branch | Fixed version | Affected scope |
|---|---|---|
| cPanel & WHM 11.110 | 11.110.0.137 | Versions before 11.110.0.137 |
| cPanel & WHM 11.118 | 11.118.0.71 | Versions before 11.118.0.71 |
| cPanel & WHM 11.126 | 11.126.0.78 | Versions before 11.126.0.78 |
| cPanel & WHM 11.134 | 11.134.0.48 | Versions before 11.134.0.48 |
| cPanel & WHM 11.136 | 11.136.0.32 | Versions before 11.136.0.32 |
| WP Squared | 138.1.6 | Versions before 138.1.6 |
The retrieved NVD data does not contain a complete affected-version configuration. The version ranges above come from available advisory information and should be used for triage while administrators confirm their installation state through the vendor’s update and version-reporting mechanisms. Systems on unsupported or end-of-life branches require additional care because the listed fixed build may not be available through the normal update channel.
A server should be considered potentially affected if its installed cPanel build is below the fixed build for its branch. Hosting providers should inventory every cPanel node, including backup, staging, reseller, and disaster-recovery systems. WP Squared administrators should separately verify the installed WP Squared version rather than assuming that a cPanel update also updates that product.
CVSS Score Breakdown
CVE-2026-93698 has a reported CVSS score of 9.9, placing it in the critical severity category. The score signals potentially severe impact and a high priority for remediation, particularly on internet-facing hosting infrastructure.
The retrieved NVD record does not provide a CVSS vector. The individual components, including attack vector, attack complexity, privileges required, user interaction, scope, confidentiality, integrity, and availability, cannot be accurately enumerated. The quick-reference table therefore records attack vector and authentication requirements as unspecified rather than guessing from the numeric score.
The supplemental description that unauthorized users may execute commands suggests a potentially low-friction attack path, but that wording is not sufficient to reconstruct a valid CVSS vector. Security teams should use the 9.9 score for prioritization while avoiding unsupported assumptions about whether exploitation requires a network-accessible administrative endpoint, credentials, or a particular user role.
Exploitation Status
CISA’s Known Exploited Vulnerabilities catalog does not list CVE-2026-93698. There is no CISA-assigned KEV due date or required remediation action for this CVE based on the retrieved result. Absence from KEV does not prove that exploitation has not occurred; it means the CVE was not present in the catalog at the time of the assessment.
No credible public proof-of-concept repository was identified in the available search results, and no confirmed in-the-wild exploitation evidence was identified. The current assessment is therefore: public PoC not known, confirmed exploitation not known, and CISA KEV listing absent. Because the flaw permits potential arbitrary command execution and has a 9.9 severity rating, organizations should not wait for a public exploit before patching.
Analyst’s Take: The missing CVSS vector and unconfirmed attack sequence limit what can be inferred about exploit preconditions. They do not reduce the operational priority: patch affected cPanel and WP Squared systems to the listed fixed builds, then investigate administrative-component activity on systems that could not be updated promptly.
How to Detect It
Detection should focus on unexpected use of cPanel administrative components, unusual child processes, changes to hosted accounts, and commands launched by service identities. Review activity from the time the vulnerable build was installed or exposed, prioritizing externally reachable management interfaces and servers hosting sensitive or high-value tenants.
A clean log review cannot prove that a server was not compromised. Command execution may occur through a component that does not preserve the full original request, and attackers can delete or alter local evidence. Correlate cPanel logs with web access logs, SSH authentication records, endpoint telemetry, file-integrity monitoring, process events, and outbound network connections.
For additional endpoint triage after suspicious activity, administrators may use a reputable malware-scanning solution such as Malwarebytes alongside forensic review and incident-response procedures. Scanning is a supporting control, not proof that a server is clean.
Technical Notes
The following searches are starting points for collected cPanel and system logs. File paths and field names vary by deployment, so adapt them to the local logging pipeline:
# Confirm the installed cPanel version
/usr/local/cpanel/cpanel -V
# Search common cPanel and system logs for administrative activity
grep -R -i -E \
'multilang|adminbin|/execute/|cmd=|command=|shell=|/bin/sh|/bin/bash' \
/usr/local/cpanel/logs /var/log 2>/dev/null
# Review recently modified executable or script content in hosted areas
find /home -type f \( -name '*.php' -o -name '*.cgi' -o -name '*.pl' -o -name '*.sh' \) \
-mtime -14 -printf '%TY-%Tm-%Td %TH:%TM %u %p\n' 2>/dev/null
In a SIEM, hunt for process creation where a cPanel-related service or web-facing process spawns shells, interpreters, download utilities, or command-execution tools. A generic detection condition is a parent process associated with cPanel or its administrative web service followed by a child process such as sh, bash, perl, python, php, curl, wget, or nc. This is a behavioral lead, not a confirmed CVE-specific signature.
Mitigation and Patching
Upgrade each cPanel & WHM server to at least the fixed build for its release branch: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, or 11.136.0.32. WP Squared installations should be upgraded to 138.1.6 or later. Verify the installed version after updating and record the result in the organization’s asset inventory.
For a repeatable remediation process, use this incident alongside a documented vulnerability patching playbook. Because the flaw may allow arbitrary command execution through an administrative component, treat patching as an urgent change even though the CVE is not currently in CISA KEV.
If a system cannot be patched immediately, restrict administrative access to trusted management networks or VPNs, enforce strong authentication and least privilege, and increase monitoring. These controls reduce exposure but do not remediate the underlying validation flaw.
Technical Notes
For cPanel & WHM, the standard update script can be used to force an update through the configured update tier:
/usr/local/cpanel/scripts/upcp --force
/usr/local/cpanel/cpanel -V
The command updates the server according to its configured cPanel release channel; it should not be treated as a guarantee that a specific branch will be selected. Administrators should confirm that the resulting version is at or above the applicable fixed build. Coordinate updates with hosting operations because service restarts or configuration changes may affect customer workloads.
If immediate patching is impossible, remove unnecessary internet exposure for WHM and cPanel management services, allow access only from approved administrator networks, and review firewall and reverse-proxy rules. Do not rely on a firewall workaround as a permanent fix, especially when reseller, automation, monitoring, or customer workflows may still reach the affected component.
After patching, investigate suspicious command execution, new administrator or reseller accounts, modified cron entries, SSH keys, unexpected files, outbound connections, and changes to hosted applications. If evidence of command execution is found, isolate the server and follow incident-response procedures rather than treating the update alone as sufficient recovery.
References
- NVD record and references for CVE-2026-93698
- cPanel 110 change log
- cPanel 134 change log
- cPanel 136 change log
- cPanel 138 change log
- WP Squared change log
- Cyber Security Agency of Singapore alert AL-2026-097
- CISA Known Exploited Vulnerabilities Catalog
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.