SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67398

HIGH · CVSS 8.2 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the 2Checkout payment gateway of WHMCS versions prior to 8.13.8 and 9.0.8, as well as all EOL versions from 4.5.0, allows unauthenticated users to access sensitive customer data through specific endpoints. This poses a significant risk to customer privacy and data security, making it critical for organizations using affected WHMCS versions to prioritize patching and upgrading to mitigate potential data breaches.

CVE
CVE-2026-67398
Severity
HIGH
CVSS
8.2
EPSS
0.28%

Original NVD Description

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.