PT-2026-85205 · Whmcs · Whmcs

·

CVE-2026-67398

·

Published

2026-09-03

·

Updated

2026-09-04

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WHMCS versions 4.5.0 through 8.13.7 WHMCS versions 8.13.0 through 8.13.7 WHMCS versions 9.0.0 through 9.0.7
Description A missing authorization issue exists in the 2Checkout payment gateway. This flaw allows an unauthenticated user to retrieve customer data through the 2Checkout payment gateway endpoint under specific conditions.
Recommendations Update to version 8.13.8 or later. Update to version 9.0.8 or later. Update to a supported version beyond the EOL 4.5.0 range.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67398

Affected Products

Whmcs