logo

Attackers Exploit cPanel Authentication Bypass 0-Day After PoC Release

ID: 61970b90-c3e8-5598-b10a-5656f48aa7f0

STIX ID: report--61970b90-c3e8-5598-b10a-5656f48aa7f0

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

A critical CVE-2026-41940 zero-day in cPanel/WHM (CVSS 9.8) is actively exploited via a CRLF injection in the session load/save flow, allowing unauthenticated attackers to inject tokens to bypass authentication and achieve root RCE; a PoC has been published and numerous hosting providers are being targeted. The advisory lists affected branches and patched releases, detection indicators (e.g., injected cp_security_token, multi-line passwords, successful_external_auth_with_timestamp), and mitigation steps including immediate patching, session purging, forced password resets, and blocking control-panel ports if necessary.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.