CVE-2026-93697: XSS
Published Oct 2, 2026
·Updated
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
Affected Software
1 affected component
Cpanel WHM
Event History
Oct 2, 2026
CVE Published
via MITRE·06:20 AM
Data Sourced
via MITRE·06:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs low-level privileges and must be able to cause a user to interact with the stored malicious content. The vector is network-accessible, and the impact includes high confidentiality, integrity, and availability effects across a changed security scope.
2
Which interface is affected?
The vulnerability affects the WHM Mass Modify Accounts interface. The referenced cPanel security advisory describes it as affecting WHM account-modification interfaces.