LOWVulnerability
CVE-2026-67398
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.
Properties
- cve_id
- CVE-2026-67398
- signal_observed_at
- 2026-09-15T21:20:01+00:00
- published_at
- 2026-09-04T00:17:13.563
- last_modified
- 2026-09-14T21:17:25.283
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Missing Authorization
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph