CVE-2026-67398

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 00:17

Updated : 2026-09-14 21:17


NVD link : CVE-2026-67398

Mitre link : CVE-2026-67398

CVE.ORG link : CVE-2026-67398


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization