CVE Field Guide
About Us
CVE-2026-93698
PUBLISHED
Assigner:
hackerone
Reserved:
18.09.2026
Published:
02.10.2026
Updated:
02.10.2026
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
Metrics
CVSS 3.0
CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score:
9.9
CVSS score
9.9
Attack Vector
Network
Scope
Changed
Attack Complexity
Low
Confidentiality Impact
High
Privileges Required
Low
Integrity Impact
High
User Interaction
None
Availability Impact
High
CVSS 3.0
Product Status
Vendor
Webpros
Product
cPanel
Versions
Default:
unaffected
affected from 0 to 11.138.0.11 (excl.)
affected from 0 to 11.136.0.45 (excl.)
affected from 0 to 11.134.0.61 (excl.)
affected from 0 to 11.110.0.148 (excl.)
Vendor
Webpros
Product
WP Squared
Versions
Default:
unaffected
affected from 0 to 11.138.1.13 (excl.)
Credits
rz1027 (rz1027)
finder
References
https://hackerone.com/reports/4054291
https://support.cpanel.net/hc/en-us/articles/43845931719447-Security-CVE-2026-93698-Vulnerability-in-Multilang-Adminbin-September-29-2026
https://docs.cpanel.net/changelogs/138-change-log/#138011
https://docs.cpanel.net/changelogs/136-change-log/#136045
https://docs.cpanel.net/changelogs/134-change-log/#134061
https://docs.cpanel.net/changelogs/110-change-log/#1100148
https://docs.wpsquared.com/changelogs/versions/changelog/#138113
Problem Types
CWE-78 OS Command Injection
CWE