CVE-2026-29204: Critical severity WHMCS WHMCS vulnerability
Insufficient ownership check in clientarea.php allows an authenticated client area user to submit requests using another user’s addonId without any ownership validation leading to unauthorized access to the victim's account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29204?
CVE-2026-29204 is classified as a high severity vulnerability due to its potential to allow unauthorized access to sensitive account information.
How do I fix CVE-2026-29204?
To fix CVE-2026-29204, ensure that ownership checks are properly implemented in clientarea.php to prevent users from accessing other users' addonIds.
Who is affected by CVE-2026-29204?
CVE-2026-29204 affects users of WHMCS who can authenticate within the client area but lack proper ownership validation in the application.
What are the risks associated with CVE-2026-29204?
The risks associated with CVE-2026-29204 include unauthorized access to another user's account and potential misuse of their sensitive data.
Is there a patch available for CVE-2026-29204?
Yes, WHMCS recommends applying the latest security updates or patches that address the ownership validation issue related to CVE-2026-29204.