logo

Critical cPanel Vulnerability Lets Attackers Bypass Login, Gain Root Access

ID: bcb87904-4ded-5b3b-b95b-34479fc3c8ca

STIX ID: report--bcb87904-4ded-5b3b-b95b-34479fc3c8ca

Feed Name: HackRead

Threat Score
95/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Deeba Ahmed

...
...

Researchers at watchTowr Labs disclosed CVE-2026-41940, a critical (CVSS 9.8) authentication-bypass vulnerability in cPanel & WHM's cpsrvd session handling that allows attackers to inject CRLF into session files and escalate to root without credentials; exploitation was observed in the wild as a 0-day since February 2026, patches were released on 28 April 2026, and detection artifacts were published to help administrators identify compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.