Junglewise Threat Intelligence

CVE-2026-67399: WHMCS deserialization of untrusted data remote code execution

CVE-2026-67399 · Severity: info · CVSS 9.8 · Published 2026-09-14

Technologies: WHMCS. Vendors: WHMCS.

Executive brief

WHMCS is a widely-used billing and client management system for hosting providers and web service companies. An unauthenticated attacker can submit forged payloads to exploit unsafe deserialization, achieving remote code execution and complete compromise of the WHMCS installation, its customer data, and the underlying server.

Technical details

The vulnerability is a PHP deserialization flaw in WHMCS 8.0.x and later versions that fails to properly validate or restrict forged payloads before processing them. An unauthenticated remote attacker can craft malicious serialized objects and submit them to a vulnerable endpoint, triggering unsafe deserialization that leads to arbitrary code execution with server privileges. The attack requires no prior authentication or user interaction. The flaw affects all 9.x versions before 9.0.8 and all 8.x versions before 8.13.7; patches are available in WHMCS 9.0.8 and 8.13.7 respectively.

Affected products

  • WHMCS WHMCS 8.0.0 before 8.13.7, 9.0.0 before 9.0.8

Timeline

  • 2026-09-03: disclosed: WHMCS published security advisory
  • 2026-09-03: patched: Fixes available in WHMCS 9.0.8 and 8.13.7
  • 2026-09-14: advisory: CVE-2026-67399 published on NVD

References

Related threats