CVE-2026-93029: XSS
Published Oct 2, 2026
·Updated
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Affected Software
1 affected component
Cpanel WHM
Event History
Oct 2, 2026
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack vector indicates network reachability, low attack complexity, and low privileges required. Exploitation also requires user interaction.
2
What could a successful exploit allow?
The vulnerability is described as stored XSS allowing arbitrary code execution in the WHM Manage SSL Hosts interface. Its impact metrics indicate high confidentiality, integrity, and availability impact, including impact beyond the initially affected security authority.