CVE-2026-67399 - WHMCS Security Update 2026-09-03
Situation
A security vulnerability (CVE-2026-67399) has been identified in WHMCS 8.0.x and later involving the submission of forged payloads without adequate restrictions. Under specific conditions, an attacker could use this submission to achieve remote code execution on the server.
This issue was responsibly disclosed through our security program and is currently being addressed.
Impact
An unauthenticated user could leverage this flaw to execute arbitrary code on the WHMCS host, resulting in full compromise of the installation and its data.
Affected versions include:
All WHMCS 9.x builds prior to 9.0.8.
All WHMCS 8.x builds prior to 8.13.7.
Call to Action
We have released a fix for this in the following WHMCS versions:
WHMCS 9.0.8
WHMCS 8.13.7
Update immediately to the latest WHMCS version after the patched release is available.