CVE-2026-67399

Summary

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
WebProsWHMCS9.0.0 < 9.0.8affected
WebProsWHMCS8.0.0 < 8.13.7affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of Untrusted Data

References