Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.
References
| Link | Resource |
|---|---|
| https://help.whmcs.com/m/125386/l/2073908-cve-2026-29204 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-12 18:16
Updated : 2026-06-17 10:29
NVD link : CVE-2026-29204
Mitre link : CVE-2026-29204
CVE.ORG link : CVE-2026-29204
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
