Temporary Advertisements:
Ad
Ad
Ad
[HOT] CVE-2026-41940: cPanel/WHM Auth Bypass to ROOT - 0-Day Chain Breakdown & PoC
by Zfruussia - Friday May 1, 2026 at 01:56 PM
#1
Greetings,
Massive leak in the hosting world today. CVE-2026-41940 is a critical Authentication Bypass in cPanel & WHM that grants full ROOT access without a password. This is already being exploited in the wild.
The Impact: cPanel runs on ~70M+ sites. Since this hits the WHM layer, we are talking about a full server takeover. One successful hit = total control over every site, DB, and mail on that box.
The Exploit Chain (5 Steps):
  1. Initial Hit: Send a malformed login request. cPanel generates a temp session file and hands you a cookie.
  2. Flag Flip: Modify a specific flag in the cookie to force the password field to be stored as plaintext.
  3. CRLF Injection: Send a "login" with
     
    \n
    (newline) smuggled into the password. The unsanitized input injects fake lines into the session file:
     
    user=root
    and
     
    authenticated=1
    .
  4. Poisoning: Hit any page to force cPanel to reload the poisoned session file into memory.
  5. Win: Next request, the server sees you as "already authenticated" root. No password check, no 2FA.
Vulnerable Builds (Anything below these is toast):
  • 110.0.x < 11.110.0.97
  • 118.0.x < 11.118.0.63
  • 126.0.x < 11.126.0.54
  • 132.0.x < 11.132.0.29
  • 134.0.x < 11.134.0.20
  • 136.0.x < 11.136.0.5
Detection Tool (PoC): watchTowr has released a scanner to verify the bypass:
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
Full Write-up for the nerds: The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
Pro-Tip: If you're scanning, watch out for cPHulk. You might need to rotate IPs or use clean proxies to avoid the rate limit.
Don't forget to +REP if this helps your research!
Reply
#2
thank you so much
Reply
#3
https://github.com/ynsmroztas/cPanelSniper

Here's a really great script with more functionality
Reply
#4
(May 03, 2026, 12:10 AM)phas3lock Wrote: https://github.com/ynsmroztas/cPanelSniper

Here's a really great script with more functionality

thanks bro
Reply
#5
thanks bro
Reply
#6
+rep bro looks nice
Reply
#7
Wow, it really is true. it will be long time to catch up with patching. there are tons of small businesses that wont know what this is. 
Link: https://www.cybersecuritydive.com/news/c...8/Critical vulnerability in cPanel leads to widespread exploitationResearchers warn that threat activity continues to surge, including brute force attacks and ransomware.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching. If you feel this is incorrect: https://breached.hn/Forum-Ban-Appeals
Reply
#8
(May 05, 2026, 12:49 PM)windbreaker89 Wrote: Wow, it really is true. it will be long time to catch up with patching. there are tons of small businesses that wont know what this is. 
Link: https://www.cybersecuritydive.com/news/c...8/Critical vulnerability in cPanel leads to widespread exploitationResearchers warn that threat activity continues to surge, including brute force attacks and ransomware.

Found a few on Shodan on a limited results search
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 35 5,929 Sep 19, 2026, 10:23 PM
Last Post: agus123
  Breached forums and clones? fda5b 8 3,320 Sep 19, 2026, 05:33 PM
Last Post: binaryplay
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 24 4,667 Sep 18, 2026, 04:17 PM
Last Post: krassimiryo
  Claude Mythos biyukean 7 1,195 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 20,555 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz

Forum Jump:


 Users browsing this forum: 1 Guest(s)