CVE-2026-41940: Zero-Day Authentication Bypass in cPanel & WHM
ID: f75e1e02-1e5a-5d8b-ad8c-aa18f081c0e5
STIX ID: report--f75e1e02-1e5a-5d8b-ad8c-aa18f081c0e5
Feed Name: Security Boulevard
**CVE-2026-41940 — Critical cPanel & WHM zero-day:** A CRLF injection and session-handling flaw in the cpsrvd daemon allows unauthenticated attackers to craft session cookies and Authorization headers that write privileged fields (e.g., user=root, hasroot=1, tfa_verified=1) into on-disk session files, which are then promoted into the JSON cache and treated as fully authenticated root sessions; public PoC and active exploitation were observed from ~Feb 23, 2026 through disclosure on Apr 28, 2026, with ~44,000 IPs scanning/exploiting and ~650,000 exposed instances, enabling full server compromise, credential theft, MFA bypass, and widespread persistence unless patched and thoroughly hunted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
