Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.
References
| Link | Resource |
|---|---|
| https://help.whmcs.com/m/125386/l/2073908-cve-2026-29204 |
Configurations
No configuration.
History
12 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| References |
|
|
| Summary | (en) Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account. |
12 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 18:16
Updated : 2026-05-13 15:54
NVD link : CVE-2026-29204
Mitre link : CVE-2026-29204
CVE.ORG link : CVE-2026-29204
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
