CVE-2026-29204Patch

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-13); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-12: 2Mentions · 2026-05-13: 3Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-13: 3Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 105-1205-1305-14
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-122
Disclosure2
2026-05-133
Patch3
2026-05-141
General1
Full discourse6 posts
  • 1024@1024DevHub
    Patch

    各位VPS商家,赶紧更新啦! WHMCS漏洞,影响7.4.0及之后的所有版本,建议立即更新 https://help.whmcs.com/m/125386/l/2073908-cve-2026-29204

    Post summary

    VPS providers are urged to update WHMCS immediately because of CVE-2026-29204, but no exploitation details or technical specifics are provided.

    1800213.1K
    18.9K followersView on X
  • Mohammad@Linuxmaster14
    General

    @syntax_teror How about WHMCS :D CVE-2026-29204

    Post summary

    The tweet merely references CVE-2026-29204 without any additional information.

    10020238
    4.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🚨 WHMCS 7.4 ve üzeri sürümlerde CVE skoru 9.1 olan CVE-2026-29204 kritik açık duyuruldu. Bu yazılımı kullananlar mutlaka son sürüme güncellesinler. * WHMCS 8.x -> WHMCS 8.13.3'e güncelleyin. * WHMCS 9.x -> WHMCS 9.0.4'e güncelleyin * WHMCS 7.X -> 9.0.4 veya 8.13.3'e yükseltin.

    Post summary

    Critical CVE-2026-29204 with a 9.1 score is highlighted for WHMCS 7.4+ users, providing explicit upgrade instructions to mitigate the vulnerability.

    00011182
    745 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29204 Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to submit requests using another user’s `addonId` without any ownership vali… https://www.cve.org/CVERecord?id=CVE-2026-29204

    Post summary

    The text announces CVE‑2026‑29204, describing insufficient ownership checks in `clientarea.php` that let authenticated users manipulate other users’ addon IDs, but no PoC, exploit, patch, or active exploitation details are provided.

    00001158
    57.5K followersView on X
  • whmcs.com.ua@ru_whmcs
    Patch

    Обновления безопасности (CVE-2026-29204), а также полные версии WHMCS 8.13.3 и 9.0.4 доступны для скачивания. Обновления доступны штатными средствами или вручную в виде патчей.

    Post summary

    The text announces a security update for CVE-2026-29204 and notes that patches and newer WHMCS versions are available to mitigate the issue.

    000006
    91 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-29204 Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to submit requests using anot… CVSS 10.0 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-29204 #HP #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-29204 as a critical flaw involving ownership checks in clientarea.php, rated CVSS 10.0, with no patch or evidence of exploitation yet.

    00000145
    90 followersView on X

Explore more