CVE-2026-41940: Critical cPanel Authentication Bypass Actively Exploited

A critical authentication bypass vulnerability in cPanel and WHM is being actively exploited in the wild, granting attackers full root-level access to vulnerable servers. The flaw, tracked as CVE-2026-41940, carries a CVSS score of 9.8 and has been weaponized since at least February 2026—months before its public disclosure on April 28.

The Vulnerability: CRLF Injection in Session Handling

CVE-2026-41940 resides in the cpsrvd (cPanel service daemon) login process. Before authentication occurs, the daemon writes session files to disk. Attackers can inject Carriage Return Line Feed (CRLF) characters through a malicious basic authorization header, manipulating the whostmgrsession cookie to insert arbitrary properties—including user=root.

This bypasses the entire authentication flow, allowing unauthenticated remote attackers to establish administrative sessions without credentials. No user interaction is required, and the exploit works against any internet-exposed cPanel or WHM instance running affected versions.

Impact: Full Server Compromise

Successful exploitation grants attackers comprehensive control over the target system:

  • Root Access via WHM: Complete administrative control over the server
  • Account Takeover: Access to all customer hosting accounts via cPanel
  • Data Theft: Full access to websites, databases, email accounts, and credentials
  • Persistence: Ability to deploy backdoors, create new users, or modify server configurations
  • Malware Deployment: Compromised servers can be used for phishing, spam, or further attacks

An estimated 1.5 million cPanel instances are exposed to the internet, making this one of the most widely impactful server-side vulnerabilities disclosed in 2026.

Affected Versions

The vulnerability impacts cPanel and WHM versions after 11.40. Patched versions include:

  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.132.0.29
  • 11.134.0.20
  • 11.136.0.5

WP Squared version 136.1.7 is also affected and requires updating.

Emergency Response: CISA Issues May 3 Deadline

CISA has added CVE-2026-41940 to its Known Exploited Vulnerabilities Catalog, mandating that Federal Civilian Executive Branch agencies apply patches by May 3, 2026. This accelerated timeline reflects confirmed active exploitation in the wild.

cPanel released emergency security updates on April 28, 2026. Server administrators should update immediately—delaying patching exposes systems to trivial exploitation with publicly available proof-of-concept code.

Temporary Mitigations

If immediate patching is not feasible, administrators can implement these temporary measures:

  • Firewall Rules: Block inbound traffic on ports 2083, 2087, 2095, and 2096
  • Service Stop: Temporarily stop cpsrvd and services (note: this disables cPanel access entirely)
  • Access Monitoring: Audit WHM access logs for unusual administrative activity, including account creation, configuration changes, or data exports

cPanel has also released a detection script to check for indicators of compromise and suspicious sessions in the filesystem. Administrators should run this script post-patching to verify whether their systems were targeted during the exposure window.

Why This Matters

CVE-2026-41940 demonstrates how a single injection flaw in session handling can completely bypass authentication—a reminder that pre-authentication code paths require rigorous scrutiny. The months-long gap between initial exploitation (February) and disclosure (April) underscores the risk of silent zero-day campaigns targeting hosting infrastructure.

For managed hosting providers, this vulnerability highlights the importance of automated patch deployment and real-time intrusion detection. A single unpatched server can lead to mass compromise across thousands of customer accounts.


Update immediately. This is not a vulnerability you can wait on.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer