CVE-2026-67398 - WHMCS Security Update 2026-09-03
Situation
A security vulnerability (CVE-2026-67398) has been identified in WHMCS 4.5.0 and later involving the 2CheckOut payment gateway module. Under specific conditions, an attacker could retrieve customer data.
This issue was responsibly disclosed through our security program and is currently being addressed. We would like to thank boomerang for responsibly disclosing this vulnerability.
Impact
An unauthenticated user could leverage this flaw to retrieve personally identifiable information (PII) for a client, including the client's name, address, city, state, postal code, country, email, and phone number.
Affected versions include:
All WHMCS 9.x builds prior to 9.0.8.
All WHMCS 8.x builds prior to 8.13.7.
A fix is only available for supported WHMCS versions. If you are running WHMCS 4.5 or later, you must upgrade to WHMCS 9.0.8 or WHMCS 8.13.7.
Call to Action
We have released a fix for this in the following WHMCS versions:
WHMCS 9.0.8
WHMCS 8.13.7
Update immediately to the latest WHMCS version after the patched release is available.
Temporary Workaround
As a temporary workaround, you can deactivate the 2CheckOut module on your WHMCS installation.
To do this:
Go to Configuration > System Settings > Payment Gateways.
Click Deactivate for the 2CheckOut payment gateway module.
Select an alternative payment gateway. The system will automatically reassign any services, invoices, transactions, and pay methods to this new payment gateway.