---
id: CVE-2026-67399
title: >-
  Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before
  8.13.7 allows remote attackers to execute arbitrary code.
summary: >-
  Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before
  8.13.7 allows remote attackers to execute arbitrary code.
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-502
vendor: WebPros
product: WHMCS
affected:
  - WHMCS >= 9.0.0 < 9.0.8
  - WHMCS >= 8.0.0 < 8.13.7
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:04:14.413'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67399'
references:
  - url: >-
      https://help.whmcs.com/m/125386/l/2118034-cve-2026-67399-whmcs-security-update-2026-09-03
    label: support@hackerone.com
tags:
  - nvd
  - cve.org
epss: 0.00752
epssPercentile: 0.53069
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-15T13:28:16.542784Z'
cvssSource: cna
ingestedAt: '2026-09-14T21:15:17.461Z'
---

## Overview

Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
