Junglewise Threat Intelligence

CVE-2026-29204: WHMCS authorization bypass in clientarea.php via addonId

CVE-2026-29204 · Severity: critical · CVSS 9.1 · Published 2026-05-12

Technologies: WHMCS. Vendors: WHMCS.

Executive brief

WHMCS is a popular automation platform used by web hosts to manage billing and customer support. A security flaw in the customer portal allows a logged-in user to manipulate request parameters to access or control services belonging to other customers. This could lead to unauthorized access to sensitive account data or linked hosting services like cPanel.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in `clientarea.php` due to insufficient ownership validation of the `addonId` parameter. While the attacker must be authenticated as a valid client, the application fails to verify if the requested `addonId` belongs to the active session user. This allows an attacker to submit requests on behalf of other users, potentially gaining unauthorized access to victim resources, including linked cPanel accounts. The vulnerability affects WHMCS versions 7.4.0 through 9.0.3 and has been patched in versions 8.13.3 and 9.0.4.

Affected products

  • WHMCS WHMCS 7.4.0 through 8.13.2, 9.0.0 through 9.0.3

Timeline

  • 2026-05-12: disclosed: Responsibly disclosed via security program
  • 2026-05-12: advisory
  • 2026-05-12: patched: Fixed in WHMCS 9.0.4 and 8.13.3

References

Related threats