Arbitrary Command Execution Vulnerability in cPanel Multilang
CVE-2026-93698

9.9CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
2 October 2026

What is CVE-2026-93698?

The cPanel Multilang Adminbin is affected by a security vulnerability that stems from insufficient validation. This issue potentially enables attackers to execute arbitrary commands, leading to unauthorized actions on the system. Users of the affected versions should prioritize patching to mitigate exposure and maintain security integrity.

Affected Version(s)

cPanel 0 < 11.138.0.11

cPanel 0 < 11.136.0.45

cPanel 0 < 11.134.0.61

References

CVSS V3.0

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rz1027 (rz1027)
.