CVE-2026-67399
largeUnauthenticated Remote Code Execution via Deserialization in WHMCS 8 and 9
WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 contains a deserialization of untrusted data flaw (CWE-502) that lets a remote attacker achieve arbitrary code execution. The CVSS 4.0 score of 9.3 (critical) with no privileges and no user interaction required indicates it can be triggered unauthenticated, by sending a crafted serialized payload to an affected WHMCS installation which is then deserialized by the application. Successful exploitation gives the attacker code execution on the web server, exposing billing records, customer and payment data, API credentials, and potentially connected hosting-control-panel infrastructure. All operators running WHMCS 9.0.0–9.0.7 or 8.0.0–8.13.6, especially internet-facing billing deployments, are affected. As of now there is no known public proof of concept, no CISA KEV listing, and no confirmed in-the-wild exploitation.
What to do: Upgrade immediately to WHMCS 9.0.8 or 8.13.7 or later; confirm your version in the WHMCS admin area before and after patching. Until patched, restrict access to the WHMCS installation (IP allowlisting/WAF rules on admin and client-facing endpoints) and monitor web server logs for unusual POST requests containing serialized PHP objects. After remediation, rotate WHMCS database credentials, API keys, and any stored server/hosting-panel credentials, and review logs for indicators of prior compromise.
| WHMCS (WebPros) WHMCS | 9.0.0 up to and including versions before 9.0.8 (i.e., 9.0.0 - 9.0.7) |
| WHMCS (WebPros) WHMCS | 8.0.0 up to and including versions before 8.13.7 (i.e., 8.0.0 - 8.13.6) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
- Weakness
- CWE-502
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.