Description
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Published: 2026-09-14
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in WHMCS through deserialization of untrusted data, allowing a remote attacker to spawn arbitrary code on the affected installation. The weakness is classified as unsafe deserialization (CWE-502), a failure to verify or isolate input that may be crafted by an attacker. The impact is broad; any user who can trigger the deserialization path can achieve full control of the web server, leading to data theft, site takeover, or distribution of malware.

Affected Systems

WHMCS versions 9.0.0 through 9.0.7 and 8.0.0 through 8.13.6 are impacted. The fix is available in version 9.0.8 and 8.13.7 and later releases. Only installations using those older versions are susceptible.

Risk and Exploitability

The CVSS score of 9.3 marks the flaw as critical. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is remote and requires only the ability to supply input that triggers deserialization, making it likely exploitable over the web without local user privileges.

Generated by OpenCVE AI on September 15, 2026 at 08:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the WHMCS security update to reach version 9.0.8 or later, or upgrade to 8.13.7 or later if using the 8.x branch
  • Ensure the WHMCS installation is correctly configured to prevent unauthorized access to functions that trigger deserialization, such as disabling or restricting the API, templates, or custom modules that may pass data to deserialization routines
  • Continuously monitor web server logs for signs of deserialization attempts or other suspicious activity

Generated by OpenCVE AI on September 15, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros whmcs
Vendors & Products Webpros
Webpros whmcs

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-14T20:53:05.620Z

Reserved: 2026-07-29T15:00:02.294Z

Link: CVE-2026-67399

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:25.423

Modified: 2026-09-14T21:17:25.423

Link: CVE-2026-67399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:45:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data