Description
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Published: 2026-09-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in WHMCS occurs when the application deserializes data that has not been verified or sanitized. This unsafe deserialization allows an attacker to craft an object that, when unserialized, can execute arbitrary PHP code on the server. The flaw falls under CWE‑502 and could give a remote attacker full control of the web application environment.

Affected Systems

WebPros WHMCS, versions 9.0.0 through 9.0.7 and 8.0.0 through 8.13.6, are affected. The vulnerability is resolved in releases 9.0.8 and 8.13.7 and later. Only installations running the older releases remain vulnerable.

Risk and Exploitability

The CVSS score of 9.3 marks the flaw as critical, but the EPSS score is less than 1 %, indicating a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw remotely by submitting crafted input to a deserialization endpoint, which does not require local privileges. Successful exploitation would grant the attacker the ability to execute arbitrary code, compromise data, or take control of the hosting environment.

Generated by OpenCVE AI on September 17, 2026 at 20:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WHMCS to version 9.0.8 or later or to 8.13.7 or later if using the 8.x branch
  • Restrict or disable modules and admin functions that trigger deserialization, and ensure no untrusted data is passed to PHP’s unserialize routine
  • Regularly review server logs for unusual deserialization activity and monitor for signs of exploitation

Generated by OpenCVE AI on September 17, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title WHMCS Unsafe Deserialization Enables Remote Code Execution

Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title WHMCS Unsafe Deserialization Enables Remote Code Execution

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros whmcs
Vendors & Products Webpros
Webpros whmcs

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-15T13:28:24.720Z

Reserved: 2026-07-29T15:00:02.294Z

Link: CVE-2026-67399

cve-icon Vulnrichment

Updated: 2026-09-15T13:28:20.987Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T21:17:25.423

Modified: 2026-09-18T19:04:14.413

Link: CVE-2026-67399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data