Skip to main content
Security

cPanel and WHM Authentication Bypass CVE-2026-41940 Allows Root Access

cPanel and WHM Authentication Bypass CVE-2026-41940 Allows Root Access Image: Primary
Security researchers at watchTowr Labs have disclosed a critical authentication bypass vulnerability in cPanel and WHM, a web hosting control panel platform that manages an estimated 70 million domains. The flaw, tracked as CVE-2026-41940, affects all currently supported versions of the software and has been actively exploited in the wild as a zero-day. The vulnerability stems from improper session handling in cpsrvd, the core server daemon. An attacker can craft a malicious HTTP Basic authentication request combined with a modified session cookie to inject key-value pairs into a session file on disk. By exploiting a missing output buffer segment in the cookie, the attacker can write plaintext control directives including hasroot=1 and successful_internal_auth_with_timestamp into the session state. The attack chain begins with a failed login request to mint a pre-authentication session. The attacker then sends a Basic auth header containing carriage-return and line-feed characters within the password field, paired with a session cookie stripped of its comma-separated hex key. Because the session loader prefers a JSON cache file over the raw session file, the injected lines initially remain hidden. However, by triggering a token-denied error through a request lacking a security token, the attacker forces the server to invoke a session modification routine that reads the raw file and repopulates the cache with the injected values now parsed as top-level keys. Once the cache is poisoned, subsequent requests using the same session bypass password validation entirely. The server sees successful_internal_auth_with_timestamp as set and returns AUTH_OK without consulting the system's shadow password file, granting the attacker root-level administrative access to WHM. cPanel has released patched versions across all supported release tracks, including 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5. Hosting provider KnownHost confirmed that in-the-wild exploitation was already underway before the patch was available.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from watchTowr Labs and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Microsoft details passkey-themed cloud-account phishing campaigns

Microsoft disclosed two campaigns that used third-party email delivery infrastructure and passkey-themed social engineering against enterprise accounts. In the cloud intrusions, attackers contacted employees by phone or message, d...

Products
Products

Trello releases beta automated enterprise-seat management

Atlassian says the beta of automatic seat management is now available to all Trello Enterprise customers. Administrators can set activity thresholds and schedules for the automation, which grants Enterprise seats to active free ma...

Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security AI
Security AI

Vendor study finds AI-related SOC alerts up 685% but almost all noise

A security vendor's review of roughly 16.9 million enterprise SOC alerts found about 73,000, or 0.43%, were tied to AI tools and agents, with that volume up 685% between February and June 2026. The vendor sorted the AI-related al...