A critical authentication bypass vulnerability in cPanel and WHM is being actively exploited in the wild, granting attackers full root-level access to vulnerable servers. The flaw, tracked as CVE-2026-41940, carries a CVSS score of 9.8 and has been weaponized since at least February 2026—months before its public disclosure on April 28.
The Vulnerability: CRLF Injection in Session Handling
CVE-2026-41940 resides in the cpsrvd (cPanel service daemon) login process. Before authentication occurs, the daemon writes session files to disk. Attackers can inject Carriage Return Line Feed (CRLF) characters through a malicious basic authorization header, manipulating the whostmgrsession cookie to insert arbitrary properties—including user=root.
This bypasses the entire authentication flow, allowing unauthenticated remote attackers to establish administrative sessions without credentials. No user interaction is required, and the exploit works against any internet-exposed cPanel or WHM instance running affected versions.
Impact: Full Server Compromise
Successful exploitation grants attackers comprehensive control over the target system:
- Root Access via WHM: Complete administrative control over the server
- Account Takeover: Access to all customer hosting accounts via cPanel
- Data Theft: Full access to websites, databases, email accounts, and credentials
- Persistence: Ability to deploy backdoors, create new users, or modify server configurations
- Malware Deployment: Compromised servers can be used for phishing, spam, or further attacks
An estimated 1.5 million cPanel instances are exposed to the internet, making this one of the most widely impactful server-side vulnerabilities disclosed in 2026.
Affected Versions
The vulnerability impacts cPanel and WHM versions after 11.40. Patched versions include:
- 11.110.0.97
- 11.118.0.63
- 11.126.0.54
- 11.132.0.29
- 11.134.0.20
- 11.136.0.5
WP Squared version 136.1.7 is also affected and requires updating.
Emergency Response: CISA Issues May 3 Deadline
CISA has added CVE-2026-41940 to its Known Exploited Vulnerabilities Catalog, mandating that Federal Civilian Executive Branch agencies apply patches by May 3, 2026. This accelerated timeline reflects confirmed active exploitation in the wild.
cPanel released emergency security updates on April 28, 2026. Server administrators should update immediately—delaying patching exposes systems to trivial exploitation with publicly available proof-of-concept code.
Temporary Mitigations
If immediate patching is not feasible, administrators can implement these temporary measures:
- Firewall Rules: Block inbound traffic on ports 2083, 2087, 2095, and 2096
- Service Stop: Temporarily stop
cpsrvdandservices (note: this disables cPanel access entirely) - Access Monitoring: Audit WHM access logs for unusual administrative activity, including account creation, configuration changes, or data exports
cPanel has also released a detection script to check for indicators of compromise and suspicious sessions in the filesystem. Administrators should run this script post-patching to verify whether their systems were targeted during the exposure window.
Why This Matters
CVE-2026-41940 demonstrates how a single injection flaw in session handling can completely bypass authentication—a reminder that pre-authentication code paths require rigorous scrutiny. The months-long gap between initial exploitation (February) and disclosure (April) underscores the risk of silent zero-day campaigns targeting hosting infrastructure.
For managed hosting providers, this vulnerability highlights the importance of automated patch deployment and real-time intrusion detection. A single unpatched server can lead to mass compromise across thousands of customer accounts.
Update immediately. This is not a vulnerability you can wait on.