BACK_TO_FEEDAICRIER_2
cPanel & WHM auth bypass hits hosts
OPEN_SOURCE ↗
YT · YOUTUBE// 1d agoSECURITY INCIDENT

cPanel & WHM auth bypass hits hosts

CVE-2026-41940 is a critical authentication bypass in cPanel & WHM's login/session flow that can let unauthenticated attackers reach WHM and take over hosted servers. cPanel has shipped fixed builds, and the incident is being treated as an emergency for internet-exposed panels.

// ANALYSIS

This is a management-plane compromise, not just another web app bug: if WHM falls, the attacker can inherit control over every site, database, and account on that server.

  • The vulnerability appears to stem from CRLF injection in session handling, which makes it especially dangerous because it bypasses the normal trust boundary before admin access is established
  • cPanel's advisory and third-party research both point to immediate patching as the only real fix; workarounds like blocking panel ports are stopgaps, not a finish line
  • The blast radius is large because cPanel is common in shared hosting, so one compromised host can expose many downstream customer sites at once
  • Rapid7 and NVD both frame this as an unauthenticated remote takeover issue with CVSS 9.8 severity, so defenders should treat exposed instances as high-priority assets
  • Operationally, this is a reminder that hosting control panels are crown-jewel infrastructure and deserve tighter network restriction, log review, and incident response playbooks
// TAGS
cpanel-whmsecurityinfrastructurehosted-serviceself-hosted

DISCOVERED

1d ago

2026-05-02

PUBLISHED

1d ago

2026-05-02

RELEVANCE

8/ 10

AUTHOR

Better Stack