Skip to content
eastbaycyber

CVE-2026-93698: cPanel Multilang Adminbin Command Execution

CVSS · Critical
9.9
In CISA KEV
No
Published
Oct 2
CVE explainers 8 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-02
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2026-93698 is a critical command execution flaw in cPanel’s Multilang Adminbin, rated CVSS 9.9. - Affected cPanel and WP Squared installations should be upgraded to the listed fixed builds. - CISA KEV does not list the CVE, and no credible public PoC or confirmed exploitation was identified in the available research.

Vulnerability at a Glance

CVE-2026-93698 affects cPanel & WHM and related WP Squared builds. The vulnerability involves insufficient validation in the Multilang Adminbin component and may allow arbitrary commands to execute on the server. Because cPanel commonly manages multiple websites, mailboxes, databases, and hosting accounts, compromise of the control-plane server can affect more than one application.

Field Details
CVE ID CVE-2026-93698
CVSS score 9.9
CVSS vector Not present in the retrieved NVD record
Attack vector Not specified in the retrieved NVD record
Authentication required Not specified in the retrieved NVD record
Patch available Yes
CISA KEV status Not listed
Primary impact Potential arbitrary command execution

The 9.9 score indicates a critical issue, but the available record does not include the CVSS vector. Do not infer network reachability, authentication requirements, or privileges from the score alone. A supplemental advisory summary describes the issue as potentially exploitable by unauthorized users. Confirm that detail against the complete vendor advisory before treating it as definitive.

What Is This Vulnerability?

NVD describes CVE-2026-93698 as an issue where “insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.” The root cause is inadequate validation of input or command-related data handled by the Multilang Adminbin component. In practical terms, attacker-controlled values may reach a command execution path without sufficient filtering, validation, or safe handling.

The exact request format, vulnerable code path, and required authorization context are not available in the retrieved NVD response. Supplemental advisory information characterizes the issue as allowing unauthorized users to execute commands on the server, but the precise attack sequence remains unconfirmed from the available primary material. Defenders should still treat exposed affected systems as high risk because arbitrary command execution can enable account tampering, data theft, persistence, malware deployment, or access to other hosted tenants.

Technical Notes

The key distinction is between command injection or unsafe command construction and a conventional web application authorization flaw. If an attacker can cause the Adminbin to invoke operating-system commands, the resulting permissions depend on the process identity and cPanel security controls. A low-privilege execution context may still expose hosted content, credentials, scheduled tasks, configuration files, and local service tokens.

Restricting the public web server does not necessarily eliminate exposure. cPanel and WHM installations include administrative services and supporting components that may be reachable through management interfaces, local integrations, or authenticated control-panel workflows. The complete vendor advisory is needed to establish the exact preconditions.

AnalystImpact · assess the risk

Who Is Affected?

The available advisory information identifies supported cPanel & WHM release branches before the following fixed builds as affected:

Product or branch Fixed version Affected scope
cPanel & WHM 11.110 11.110.0.137 Versions before 11.110.0.137
cPanel & WHM 11.118 11.118.0.71 Versions before 11.118.0.71
cPanel & WHM 11.126 11.126.0.78 Versions before 11.126.0.78
cPanel & WHM 11.134 11.134.0.48 Versions before 11.134.0.48
cPanel & WHM 11.136 11.136.0.32 Versions before 11.136.0.32
WP Squared 138.1.6 Versions before 138.1.6

The retrieved NVD data does not contain a complete affected-version configuration. The version ranges above come from available advisory information and should be used for triage while administrators confirm their installation state through the vendor’s update and version-reporting mechanisms. Systems on unsupported or end-of-life branches require additional care because the listed fixed build may not be available through the normal update channel.

A server should be considered potentially affected if its installed cPanel build is below the fixed build for its branch. Hosting providers should inventory every cPanel node, including backup, staging, reseller, and disaster-recovery systems. WP Squared administrators should separately verify the installed WP Squared version rather than assuming that a cPanel update also updates that product.

CVSS Score Breakdown

CVE-2026-93698 has a reported CVSS score of 9.9, placing it in the critical severity category. The score signals potentially severe impact and a high priority for remediation, particularly on internet-facing hosting infrastructure.

The retrieved NVD record does not provide a CVSS vector. The individual components, including attack vector, attack complexity, privileges required, user interaction, scope, confidentiality, integrity, and availability, cannot be accurately enumerated. The quick-reference table therefore records attack vector and authentication requirements as unspecified rather than guessing from the numeric score.

The supplemental description that unauthorized users may execute commands suggests a potentially low-friction attack path, but that wording is not sufficient to reconstruct a valid CVSS vector. Security teams should use the 9.9 score for prioritization while avoiding unsupported assumptions about whether exploitation requires a network-accessible administrative endpoint, credentials, or a particular user role.

Exploitation Status

CISA’s Known Exploited Vulnerabilities catalog does not list CVE-2026-93698. There is no CISA-assigned KEV due date or required remediation action for this CVE based on the retrieved result. Absence from KEV does not prove that exploitation has not occurred; it means the CVE was not present in the catalog at the time of the assessment.

No credible public proof-of-concept repository was identified in the available search results, and no confirmed in-the-wild exploitation evidence was identified. The current assessment is therefore: public PoC not known, confirmed exploitation not known, and CISA KEV listing absent. Because the flaw permits potential arbitrary command execution and has a 9.9 severity rating, organizations should not wait for a public exploit before patching.

Analyst’s Take: The missing CVSS vector and unconfirmed attack sequence limit what can be inferred about exploit preconditions. They do not reduce the operational priority: patch affected cPanel and WP Squared systems to the listed fixed builds, then investigate administrative-component activity on systems that could not be updated promptly.

ResponderRunbook · act now

How to Detect It

Detection should focus on unexpected use of cPanel administrative components, unusual child processes, changes to hosted accounts, and commands launched by service identities. Review activity from the time the vulnerable build was installed or exposed, prioritizing externally reachable management interfaces and servers hosting sensitive or high-value tenants.

A clean log review cannot prove that a server was not compromised. Command execution may occur through a component that does not preserve the full original request, and attackers can delete or alter local evidence. Correlate cPanel logs with web access logs, SSH authentication records, endpoint telemetry, file-integrity monitoring, process events, and outbound network connections.

For additional endpoint triage after suspicious activity, administrators may use a reputable malware-scanning solution such as Malwarebytes alongside forensic review and incident-response procedures. Scanning is a supporting control, not proof that a server is clean.

Technical Notes

The following searches are starting points for collected cPanel and system logs. File paths and field names vary by deployment, so adapt them to the local logging pipeline:

# Confirm the installed cPanel version
/usr/local/cpanel/cpanel -V

# Search common cPanel and system logs for administrative activity
grep -R -i -E \
  'multilang|adminbin|/execute/|cmd=|command=|shell=|/bin/sh|/bin/bash' \
  /usr/local/cpanel/logs /var/log 2>/dev/null

# Review recently modified executable or script content in hosted areas
find /home -type f \( -name '*.php' -o -name '*.cgi' -o -name '*.pl' -o -name '*.sh' \) \
  -mtime -14 -printf '%TY-%Tm-%Td %TH:%TM %u %p\n' 2>/dev/null

In a SIEM, hunt for process creation where a cPanel-related service or web-facing process spawns shells, interpreters, download utilities, or command-execution tools. A generic detection condition is a parent process associated with cPanel or its administrative web service followed by a child process such as sh, bash, perl, python, php, curl, wget, or nc. This is a behavioral lead, not a confirmed CVE-specific signature.

Mitigation and Patching

Upgrade each cPanel & WHM server to at least the fixed build for its release branch: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, or 11.136.0.32. WP Squared installations should be upgraded to 138.1.6 or later. Verify the installed version after updating and record the result in the organization’s asset inventory.

For a repeatable remediation process, use this incident alongside a documented vulnerability patching playbook. Because the flaw may allow arbitrary command execution through an administrative component, treat patching as an urgent change even though the CVE is not currently in CISA KEV.

If a system cannot be patched immediately, restrict administrative access to trusted management networks or VPNs, enforce strong authentication and least privilege, and increase monitoring. These controls reduce exposure but do not remediate the underlying validation flaw.

Technical Notes

For cPanel & WHM, the standard update script can be used to force an update through the configured update tier:

/usr/local/cpanel/scripts/upcp --force
/usr/local/cpanel/cpanel -V

The command updates the server according to its configured cPanel release channel; it should not be treated as a guarantee that a specific branch will be selected. Administrators should confirm that the resulting version is at or above the applicable fixed build. Coordinate updates with hosting operations because service restarts or configuration changes may affect customer workloads.

If immediate patching is impossible, remove unnecessary internet exposure for WHM and cPanel management services, allow access only from approved administrator networks, and review firewall and reverse-proxy rules. Do not rely on a firewall workaround as a permanent fix, especially when reseller, automation, monitoring, or customer workflows may still reach the affected component.

After patching, investigate suspicious command execution, new administrator or reseller accounts, modified cron entries, SSH keys, unexpected files, outbound connections, and changes to hosted applications. If evidence of command execution is found, isolate the server and follow incident-response procedures rather than treating the update alone as sufficient recovery.

References

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-10-02

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.