cPanel has shipped a fix for a critical flaw that lets a low-privileged hosting account run arbitrary commands on the server underneath it. Tracked as CVE-2026-93698 and rated 9.9 out of 10 on the Common Vulnerability Scoring System (CVSS), the bug was fixed in the cPanel and WHM update dated September 29, 2026, alongside two lower-severity scripting issues. If you operate cPanel and WHM, the safe assumption is that every account on the box can reach this flaw until you are on a patched build.
The vulnerability lives in the Multilang adminbin. In cPanel, adminbins are the privileged helpers that let an ordinary, unprivileged account request actions it cannot perform on its own; they run with the system's own root-level privileges precisely so they can do that work on the account's behalf. cPanel classifies CVE-2026-93698 as an operating-system command injection weakness (CWE-78): the Multilang adminbin does not validate its input strictly enough, so an attacker can smuggle in extra commands that then execute in that elevated context rather than within the caller's limited account.
What the score is actually telling you
The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Read in plain terms, that says the flaw is reachable over the network with low attack complexity, needs only low privileges and no user interaction, and crosses a scope boundary to inflict high impact on the confidentiality, integrity, and availability of the whole system. The one precondition, a low-privileged account, is the detail worth dwelling on, because on the kind of multi-tenant hosting cPanel was built for it is barely a precondition at all.
On a shared or reseller node, a low-privileged account is simply a customer. Anyone who buys a plan has one. So does any attacker who phishes a single customer's login or cracks one weak password. From that foothold, this bug is a path out of the tenant sandbox and into command execution on the host that every other customer on the machine shares. That is the scenario that makes a 9.9 on a hosting control panel more urgent than the raw number suggests: the blast radius is not one site, it is the server. It is the same multi-tenant breakout shape as the domain-parking root-escalation flaw cPanel patched in August, and the lesson repeats: a low-privilege precondition is no comfort when the attacker can simply buy the low privilege.
Who is affected
cPanel lists all supported branches as affected, and has published a first patched build for each. The fixes land in cPanel 11.138.0.11, 11.136.0.45, 11.134.0.61, and 11.110.0.148, and in WP Squared 11.138.1.13. Anything below the patched build for your branch is vulnerable, and end-of-life branches receive no fix and must be upgraded. That same release also closes a pair of stored scripting flaws in the WHM interface, affecting the Manage SSL Hosts tool (CVE-2026-93029) and the Mass Modify Accounts tool (CVE-2026-93697); both are lower severity than the adminbin flaw but worth clearing in the same pass.
As of the advisory, cPanel had not reported any exploitation in the wild, the flaw was not on the United States Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities catalog, and we found no public proof-of-concept exploit code. None of that is a reason to wait. The deployment footprint is enormous, the precondition is trivial on shared hosting, and a researcher reported this through a coordinated channel, which means the ingredients for a working exploit already exist somewhere.
Patch now, then hunt for abuse
The fix is an update. Servers on cPanel's automatic daily updates will pull the patched build on their own; staged, pinned, or manually managed servers stay exposed until you act. Apply it with /scripts/upcp --force or through WHM's upgrade interface, then confirm the running build is at or above the patched build for your branch.
/usr/local/cpanel/cpanel -V Branch 110 fixed in 11.110.0.148 Branch 134 fixed in 11.134.0.61 Branch 136 fixed in 11.136.0.45 Branch 138 fixed in 11.138.0.11 WP Squared 138.1 fixed in 11.138.1.13
Because no indicators of compromise have been published, hunting for abuse means watching behavior rather than matching a signature. The highest-value thing to review is privileged helper activity: unexpected child processes spawned by cPanel's adminbin layer, root-owned processes or files that trace back to an ordinary account's session, and new or modified cron jobs, SSH keys, or web shells under user home directories. cPanel records its activity under /usr/local/cpanel/logs/; correlating a customer account's actions there against surprising root-level effects on the host is the kind of cross-boundary anomaly this flaw produces. On a server where you monitor process ancestry and file integrity, a tenant account suddenly touching system paths it has no business in is the tell.
If you cannot patch in the same hour you read this, shrink the attack surface in the meantime: audit which accounts exist, remove dormant ones, enforce strong authentication on every login, and pay particular attention to reseller nodes where one compromised account reaches the most neighbors. Those steps reduce the odds that an attacker already holds the low-privileged foothold the bug requires, but they are a stopgap, not a substitute for the build update.