{"id":"CVE-2026-93698","title":"Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.","summary":"Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"Webpros","product":"cPanel","affected":["cPanel < 11.138.0.11","cPanel < 11.136.0.45","cPanel < 11.134.0.61","cPanel < 11.110.0.148","wp_squared < 11.138.1.13"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T07:16:39.027","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93698","references":[{"url":"https://docs.cpanel.net/changelogs/110-change-log/#1100148","label":"support@hackerone.com"},{"url":"https://docs.cpanel.net/changelogs/134-change-log/#134061","label":"support@hackerone.com"},{"url":"https://docs.cpanel.net/changelogs/136-change-log/#136045","label":"support@hackerone.com"},{"url":"https://docs.cpanel.net/changelogs/138-change-log/#138011","label":"support@hackerone.com"},{"url":"https://docs.wpsquared.com/changelogs/versions/changelog/#138113","label":"support@hackerone.com"},{"url":"https://hackerone.com/reports/4054291","label":"support@hackerone.com"},{"url":"https://support.cpanel.net/hc/en-us/articles/43845931719447-Security-CVE-2026-93698-Vulnerability-in-Multilang-Adminbin-September-29-2026","label":"support@hackerone.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T07:13:06.674Z","slug":"CVE-2026-93698","body":"## Overview\n\nInsufficient validation allows arbitrary commands to be executed via the Multilang adminbin.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}