---
title: 「cPanel & WHM」发现三项关键性安全漏洞
url: https://www.dataloco.com/zh/cpanel-whm
published: 2026-10-08T01:29:22+00:00
language: zh
section: 安全
source: https://www.security-next.com/191015
organizations: WebPros International, cPanel, WHM, CVE-2026-93698, CVE-2026-93697, CVE-2026-93029
publisher: Dataloco
---

# 「cPanel & WHM」发现三项关键性安全漏洞

WebPros International发布了针对其主机管理工具「cPanel & WHM」的安全更新，以修复三项关键性漏洞。这三项漏洞均被评估为「关键性（Critical）」。

该公司于2026年9月29日发布了安全更新，解决了「CVE-2026-93698」、「CVE-2026-93697」和「CVE-2026-93029」这三项漏洞。

「CVE-2026-93698」涉及组件「Multilang adminbin」的输入验证不足，可能允许以root权限执行任意操作系统命令，从而危及管理账户、网站及数据库的控制权。

根据通用漏洞评分系统「CVSSv3.0」，该漏洞的基础评分为「9.9」，其严重程度为四级中的最高级「关键性（Critical）」。攻击者需要低权限账户进行攻击。

另外两项漏洞均为存储型跨站脚本（XSS）漏洞。「CVE-2026-93697」存在于WHM的「Mass Modify Accounts」接口，未授权账户的用户可以在WHM管理员会话中执行脚本，从而以管理员身份进行操作。

## This story in other languages

- [Svenska](https://www.dataloco.com/sv/tre-kritiska-sarbarheter-i-cpanel-whm)
- [Deutsch](https://www.dataloco.com/de/webpros-international-veroffentlicht-sicherheitsupdate-fur-cpanel-whm)
- [العربية](https://www.dataloco.com/ar/asdar-thdyth-amny-lmaaalg-thlath-thghrat-hrg-fy-cpanel-whm)
- [Español](https://www.dataloco.com/es/webpros-international-lanza-actualizacion-de-seguridad-para-cpanel-y-whm)
- [Nederlands](https://www.dataloco.com/nl/webpros-international-lost-een-beveiligingsupdate-voor-cpanel-whm)
- [Türkçe](https://www.dataloco.com/tr/cpanel-ve-whmye-3-kritik-guvenlik-acigi)
- [Русский](https://www.dataloco.com/ru/obnaruzeny-tri-uiazvimosti-v-cpanel-whm)
- [Italiano](https://www.dataloco.com/it/webpros-international-rilascia-aggiornamento-di-sicurezza-per-cpanel-e-whm)
- [Indonesia](https://www.dataloco.com/id/tiga-kerentanan-kritikal-ditemukan-pada-cpanel-whm)
