logo

CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Exposes Hosting Servers to Admin Takeover

ID: d2a0810c-0b7b-544b-bf5f-5c678a0f723f

STIX ID: report--d2a0810c-0b7b-544b-bf5f-5c678a0f723f

Feed Name: SOC Prime Blog

Threat Score
92/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: SOC Prime Team

...
...

**Executive summary:** CVE-2026-41940 is a critical (CVSS 9.8) authentication-bypass in cPanel & WHM that leverages CRLF/session injection to write attacker-controlled attributes (e.g., user=root) into pre-auth session files, enabling unauthenticated administrative access; public PoC/exploit code and reports of active exploitation increase the immediate risk, with roughly 1.5 million exposed cPanel instances cited—administrators should apply vendor patches, restart cpsrvd, run the vendor detection script against /var/cpanel/sessions, purge suspicious sessions, and treat confirmed hits as incidents requiring password resets and log/persistence auditing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.