Problem
You see the following entry in the Activity Log at Configuration () > System Logs:
Configured minimum password length "<value>" is outside the permitted range 12 to 64. Using 12.
Cause
The stored value for the Minimum Password Length setting in the Security tab at Configuration () > System Settings > General Settings is outside its permitted range.
This can occur if something outside of the Admin Area changes the value. For example, something edited the WHMCS database directly, or a migration or restored backup changed the value.
If this occurs, WHMCS ignores the out-of-range stored value and uses 12 (the PCI DSS-mandated minimum) instead. The entry will recur in the log until you correct the value.
Solution
To resolve this issue:
- Go to the Security tab at Configuration () > System Settings > General Settings.
- Set Minimum Password Length to a whole number that is between
12and64. - Click Save Changes.
Last modified: 2026 September 30