CVE-2026-29204
CRITICALWHMCS 7.4.0-18.12.1, 18.13.0-18.13.2, 9.0.0-9.0.3 - Authorization Bypass via clientarea.php addonId
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-29204. PoCs published by bogdanrotariu.
AI-analyzed exploit summary This repository provides a detailed technical analysis and mitigation for CVE-2026-29204, an authorization bypass in WHMCS where a logged-in client can access foreign addon contexts via crafted requests. It includes a temporary hook-based guard to block unauthorized access and logs such attempts.
Description
Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.
Exploits (1)
This repository provides a detailed technical analysis and mitigation for CVE-2026-29204, an authorization bypass in WHMCS where a logged-in client can access foreign addon contexts via crafted requests. It includes a temporary hook-based guard to block unauthorized access and logs such attempts.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N