Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
https://hackerone.com/reports/4054291
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91198
https://docs.wpsquared.com/changelogs/versions/changelog/#138113
https://docs.cpanel.net/changelogs/138-change-log/#138011
https://docs.cpanel.net/changelogs/136-change-log/#136045