Vulnerability Description
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-67399?
CVE-2026-67399 is a documented vulnerability. Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
How severe is CVE-2026-67399?
CVSS scoring is not yet available for CVE-2026-67399. Check NVD for updates.
Is there a patch for CVE-2026-67399?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.