Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4482 articles · 179456 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-41940KEVEXPLOITEDPATCHED
cpanel · cpanel

WebPros cPanel and WHM Authentication Bypass via Login Flow

Description

A critical authentication bypass vulnerability exists in the cPanel/WHM `cpsrvd` daemon due to improper neutralization of line delimiters (CRLF) in the `whostmgrsession` cookie and `Authorization` headers. An unauthenticated remote attacker can leverage this flaw to inject malicious session parameters directly into the server's flat-file session metadata store. By injecting sequences such as `user=root`, `hasroot=1`, and `tfa_verified=1`, the attacker subverts the internal authentication logic, forcing the system to issue a valid administrative session token (`/cpsessXXXXXXXXXX/`). This grants the attacker full `root` privileges over the WHM interface and the host operating system without requiring valid credentials.

Affected Products

VendorProductVersions
cpanelcpanel11.40.0.0, 11.88.0.0, 11.96.0.0, 11.104.0.0, 11.112.0.0, 11.120.0.0, 11.126.0.0, 11.128.0.0, 11.132.0.0, 11.134.0.0, 11.136.0.0, 11.40.0.0, 11.88.0.0, 11.96.0.0, 11.104.0.0, 11.112.0.0, 11.120.0.0, 11.126.0.0, 11.128.0.0, 11.132.0.0, 11.134.0.0, 11.136.0.0, 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.136.0.5, 11.134.0.20, 11.136.0.9, 11.134.0.25, 11.132.0.31, 11.130.0.22, 11.126.0.58, 11.124.0.37, 11.118.0.66, 11.110.0.116, 11.110.0.117, 11.102.0.41, 11.94.0.30, 11.86.0.43, 11.136.1.10

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cpanelwhmcve_cpe95%
cpanelwp_squaredcve_cpe95%

References

  • https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026(vendor-advisory, patch)
  • https://docs.cpanel.net/release-notes/release-notes(release-notes)
  • https://docs.wpsquared.com/changelogs/versions/changelog/#13617(release-notes)
  • https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026(third-party-advisory)
  • https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow(third-party-advisory)

Related News (24 articles)

Tier C
Rapid7 Blog5h ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier C
Exploit-DB57d ago
[webapps] cPanel - CRLF Injection
→ No new info (linked only)
Tier D
Help Net Security71d ago
Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940)
→ No new info (linked only)
Tier D
CSO Online71d ago
cPanel flaw exposes enterprises to hosting supply-chain risks
→ No new info (linked only)
Tier D
The Hacker News72d ago
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
→ No new info (linked only)
Tier D
Heise Security72d ago
Sicherheitspatch: Abermals Sicherheitslücken in cPanel und WHM geschlossen
→ No new info (linked only)
Tier E
Hacker News78d ago
The CPanel Zero-Day Was Active for 64 Days Before Anyone Knew
→ No new info (linked only)
Tier D
The Hacker News79d ago
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
→ No new info (linked only)
Tier D
Help Net Security79d ago
Multiple threat actors actively exploit cPanel vulnerability (CVE-2026-41940)
→ No new info (linked only)
Tier D
Heise Security79d ago
cPanel/WHM: Bereits 4000 Instanzen in Deutschland attackiert
→ No new info (linked only)
Tier B
CERT-FR79d ago
Bulletin d'actualité CERTFR-2026-ACT-020 (04 mai 2026)
→ No new info (linked only)
Tier D
BleepingComputer80d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
→ No new info (linked only)
Tier E
Hacker News81d ago
CPanel CVE-2026-41940 Exploitation from a Honeypot Perspective
→ No new info (linked only)
Tier D
The Record82d ago
Federal agencies must patch cPanel bug by Sunday, CISA says
→ No new info (linked only)
Tier E
Lobsters Security82d ago
cPanel & WHM Authentication Bypass (CVE-2026-41940)
→ No new info (linked only)
Tier D
BleepingComputer83d ago
Critical cPanel and WHM bug exploited as a zero-day, PoC now available
→ No new info (linked only)
Tier D
SecurityWeek83d ago
Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
→ No new info (linked only)
Tier E
Reddit r/netsec83d ago
High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940)
→ No new info (linked only)
Tier D
Heise Security83d ago
cPanel/WHM: Unbefugte Zugriffe auf Webserver-Konfigurationstool möglich
→ No new info (linked only)
Tier C
Rapid7 Blog83d ago
CVE-2026-41940: cPanel & WHM Authentication Bypass
→ No new info (linked only)
Tier B
CCCS Canada84d ago
AL26-008 - Vulnerability affecting cPanel and WebHost Manager (WHM) - CVE-2026-41940
→ No new info (linked only)
Tier E
Reddit r/netsec84d ago
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs
→ No new info (linked only)
Tier B
CCCS Canada84d ago
cPanel security advisory (AV26-404)
→ No new info (linked only)
Tier C
VulDB84d ago
CVE-2026-41940 | cPanel/WHM prior 11.136.0.5 missing authentication
→ No new info (linked only)
CVSS 3.19.8 MEDIUM
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
11.136.0.5
CWECWE-306, CWE-20, CWE-22, CWE-73
PublishedApr 29, 2026
Last enriched57d agov17
Tags
CVE-2026-41940WP SquaredFilemanagerHelp Net SecurityCRLF Injection
Trending Score161🔥
Source articles24
Independent15
Info Completeness13/14
Missing: epss

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (2)

NONECVE-2026-9334EXP
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled
HIGHCVE-2026-9516EXP
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 29, 2026
Added to CISA KEV
Apr 29, 2026
Discovered by ZDM
Apr 29, 2026
Updated: severity, patchAvailable, tags
Apr 29, 2026
Updated: severity, patchAvailable, activelyExploited
Apr 29, 2026
Updated: iocs
Apr 29, 2026
Updated: affectedVersions
Apr 30, 2026
Updated: description, affectedVersions
Apr 30, 2026
Updated: description, tags
Apr 30, 2026
Updated: mitreAttack
May 2, 2026
Updated: description
May 2, 2026
Updated: affectedVersions
May 4, 2026
Updated: severity
May 4, 2026
Actively Exploited
May 6, 2026
Exploit Available
May 6, 2026
Patch Available
May 6, 2026
Updated: affectedVersions, severity, patchAvailable
May 7, 2026
Updated: affectedVersions, cweIds
May 11, 2026
Updated: description, tags
May 11, 2026
Updated: description
May 12, 2026
Updated: description, tags
May 12, 2026
Updated: description, severity, tags
May 26, 2026

Version History

v17
Last enriched 57d ago
v17Tier C57d ago

Updated description with technical details about CRLF injection and changed severity to MEDIUM.

descriptionseveritytags
via Exploit-DB
v16Tier D71d ago

Updated description with specific details about the attack method and added a new tag from the article.

descriptiontags
via Help Net Security
v15Tier D71d ago

Updated description with significant technical details, changed severity to CRITICAL, and added information about over 2,000 attacker source IPs involved in automated attacks.

description
via CSO Online
v14Tier D72d ago

Updated description with details about the threat actor Mr_Rot13 and added new tag 'Filemanager' and MITRE ATT&CK technique T1203.

descriptiontags
via The Hacker News
v13Tier D72d ago

Updated affected versions with new releases, changed severity to CRITICAL, added new CWE IDs, and updated patch available to 11.136.0.9.

affectedVersionscweIds
via Heise Security
v12Tier B75d ago

Updated affected versions, changed severity to HIGH, and corrected the patch available to 11.136.0.5.

affectedVersionsseveritypatchAvailable
via CCCS Canada
v11Tier B79d ago

Updated severity from NONE to HIGH.

severity
via CERT-FR
v10Tier D79d ago

Updated severity to CRITICAL and added new affected versions.

affectedVersions
via Heise Security
v9Tier D80d ago

Updated description with details on mass exploitation and changed severity to CRITICAL.

description
via BleepingComputer
v8Tier E81d ago

Updated description with detailed technical information, changed severity to HIGH, and added MITRE ATT&CK technique T1078.

mitreAttack
via Hacker News
v7Tier D83d ago

Updated severity to CRITICAL, added new technical details, and provided new affected versions and patch information.

descriptiontags
via BleepingComputer
v6Tier D83d ago

Updated severity to CRITICAL, added new affected version 11.136.0.5, and provided a more detailed description of the vulnerability.

descriptionaffectedVersions
via SecurityWeek
v5Tier D83d ago

Updated severity to CRITICAL, provided new patch version 11.136.0.5, and added new affected versions.

affectedVersions
via Heise Security
v4Tier C83d ago

Updated description with detailed technical information about the CRLF injection vulnerability and added an IOC for Shodan.

iocs
via Rapid7 Blog
v3Tier B83d ago

Updated severity to CRITICAL, added patch version 11.136.1.7, and marked the vulnerability as actively exploited.

severitypatchAvailableactivelyExploited
via CCCS Canada
v2Tier C84d ago

Updated severity to CRITICAL, marked exploit as not available, and added CVE-2026-41940 as a new tag.

severitypatchAvailabletags
via VulDB
v184d ago

Initial creation