A critical authentication bypass vulnerability exists in the cPanel/WHM `cpsrvd` daemon due to improper neutralization of line delimiters (CRLF) in the `whostmgrsession` cookie and `Authorization` headers. An unauthenticated remote attacker can leverage this flaw to inject malicious session parameters directly into the server's flat-file session metadata store. By injecting sequences such as `user=root`, `hasroot=1`, and `tfa_verified=1`, the attacker subverts the internal authentication logic, forcing the system to issue a valid administrative session token (`/cpsessXXXXXXXXXX/`). This grants the attacker full `root` privileges over the WHM interface and the host operating system without requiring valid credentials.
| Vendor | Product | Versions |
|---|---|---|
| cpanel | cpanel | 11.40.0.0, 11.88.0.0, 11.96.0.0, 11.104.0.0, 11.112.0.0, 11.120.0.0, 11.126.0.0, 11.128.0.0, 11.132.0.0, 11.134.0.0, 11.136.0.0, 11.40.0.0, 11.88.0.0, 11.96.0.0, 11.104.0.0, 11.112.0.0, 11.120.0.0, 11.126.0.0, 11.128.0.0, 11.132.0.0, 11.134.0.0, 11.136.0.0, 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.136.0.5, 11.134.0.20, 11.136.0.9, 11.134.0.25, 11.132.0.31, 11.130.0.22, 11.126.0.58, 11.124.0.37, 11.118.0.66, 11.110.0.116, 11.110.0.117, 11.102.0.41, 11.94.0.30, 11.86.0.43, 11.136.1.10 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| cpanel | whm | cve_cpe | 95% |
| cpanel | wp_squared | cve_cpe | 95% |
Updated description with technical details about CRLF injection and changed severity to MEDIUM.
Updated description with specific details about the attack method and added a new tag from the article.
Updated description with significant technical details, changed severity to CRITICAL, and added information about over 2,000 attacker source IPs involved in automated attacks.
Updated description with details about the threat actor Mr_Rot13 and added new tag 'Filemanager' and MITRE ATT&CK technique T1203.
Updated affected versions with new releases, changed severity to CRITICAL, added new CWE IDs, and updated patch available to 11.136.0.9.
Updated affected versions, changed severity to HIGH, and corrected the patch available to 11.136.0.5.
Updated severity from NONE to HIGH.
Updated severity to CRITICAL and added new affected versions.
Updated description with details on mass exploitation and changed severity to CRITICAL.
Updated description with detailed technical information, changed severity to HIGH, and added MITRE ATT&CK technique T1078.
Updated severity to CRITICAL, added new technical details, and provided new affected versions and patch information.
Updated severity to CRITICAL, added new affected version 11.136.0.5, and provided a more detailed description of the vulnerability.
Updated severity to CRITICAL, provided new patch version 11.136.0.5, and added new affected versions.
Updated description with detailed technical information about the CRLF injection vulnerability and added an IOC for Shodan.
Updated severity to CRITICAL, added patch version 11.136.1.7, and marked the vulnerability as actively exploited.
Updated severity to CRITICAL, marked exploit as not available, and added CVE-2026-41940 as a new tag.
Initial creation