Temporary Advertisements:
Ad
Ad
Ad
Technical Analysis: CVE-2026-41940 – cPanel/WHM Authentication Bypass
by Tr28 - Monday May 11, 2026 at 10:52 PM
#1
This critical vulnerability allows an unauthenticated attacker to gain root-level access to a cPanel/WHM server by bypassing the standard authentication mechanism. It is a prime example of how multiple minor logic flaws can be chained together to create a catastrophic security failure.
1. Vulnerability Root Cause: Why Did It Happen?The vulnerability is essentially an Authentication Bypass resulting from improper session data handling. It stems from three primary failures:
  • Sanitization Failure (CRLF Injection): The
     
    cpsrvd
    binary (the core cPanel service) processes "Basic Authentication" headers. While it strips NUL (
     
    \0
    ) bytes from the password field, it fails to sanitize Carriage Return/Line Feed (
     
    \r\n
    ) characters.
  • Lack of Global Filtering: The
     
    saveSession
    function, responsible for writing session data to disk, previously assumed that the data had already been cleaned by callers. However, several entry points (like Basic Auth) bypassed the
     
    filter_sessiondata
    function.
  • Encryption Bypass (No-Ob Vulnerability): cPanel normally encrypts session files. The encryption key is derived from a hex string in the session cookie (the
     
    ob
    part). If an attacker removes this hex string from the cookie, the system fails to initialize the encoder and writes the session data to the disk in plaintext.

2. The Exploitation Chain: How to Gain Root AccessAn attacker follows a 5-step "Exploitation Chain" to take over the server:
Step 1: Initialize a Pre-Auth SessionThe attacker sends a failed login request (e.g.,
 
user=root&pass=wrong
) to
 
POST /login/
.
  • Result: The server rejects the login but creates a "pre-auth" session file on the disk and issues a session cookie:
     
    whostmgrsession=:ABC_123,hex_key
    .
Step 2: Disable the EncoderThe attacker strips the encryption key from the cookie.
  • New Cookie:
    whostmgrsession=:ABC_123
  • Impact: When the server updates this session, it will now write to the file in plaintext because it cannot find the
     
    hex_key
    to start the encryption engine.
Step 3: Inject the Poisoned PayloadThe attacker sends a request using Basic Authentication. The password field contains a specially crafted CRLF payload.
  • Payload:
    password\nhasroot=1\ntfa_verified=1\nsuccessful_internal_auth_with_timestamp=1777462149
  • Result: Because of the sanitization failure, the server writes this directly to the session file. The
     
    \n
    characters force the server to interpret
     
    hasroot=1
    as a new, high-privilege configuration line.
Step 4: Poison the Cache (Cache Invalidation)cPanel reads session data from a fast JSON cache. To make the server see the injected disk data, the attacker triggers a "Token Denied" error (by sending an invalid security token).
  • Impact: The system is forced to re-read the raw session file from the disk and update the JSON cache. Now, the attacker’s "fake" privileges are loaded into the system's active memory.
Step 5: Checkmate (Authentication Bypass)The attacker requests an administrative page (e.g.,
 
/scripts2/listaccts
). The cPanel security engine checks the session and finds the injected
 
successful_internal_auth_with_timestamp
flag.
  • Outcome: As seen in the code:
     
    return $Cpanel::Server::AUTH_OK, 0;
    . The system assumes the user is already validated and never consults the
    /etc/shadow
    file for a password. The attacker is now Root.

3. The Fix: How It Was PatchedcPanel developers implemented a "defense-in-depth" strategy to close this loop:
  1. Mandatory Filtering: The
     
    saveSession
    function now calls
     
    filter_sessiondata
    internally by default. No matter where the data comes from,
     
    \r\n
    characters are stripped before hitting the disk.
  2. Deterministic Encoding: If the encryption key (
     
    ob
    ) is missing, the system no longer reverts to plaintext. It now uses a fallback
     
    hex_encode_only
    method and prefixes the data with
     
    'no-ob:'
    . This ensures that even if a payload is injected, it remains an unreadable hex string and cannot be executed as a command.
  3. Patched Versions: This vulnerability is fixed in the following versions (and later):
    • 110.0.97
    • 118.0.63
    • 126.0.54
    • 132.0.29
    • 134.0.20
    • 136.0.5
Recommendation: System administrators must update their cPanel & WHM instances immediately. This is a zero-day vulnerability that requires no valid credentials to execute.
Reply
#2
i do not understand how issues this bad can hapen in such big software
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 39 7,124 Yesterday, 08:02 PM
Last Post: nasirames
  A small note on the ParkMobile recirculation caseymorgan2026 0 117 Yesterday, 03:22 PM
Last Post: caseymorgan2026
  The Kurdistan Ministry of Electricity in Iraq was Hacked By Old Warrior OldWarri0r 4 769 Sep 27, 2026, 12:34 PM
Last Post: qoqsik
  Saudi Arabia’s Water Facilities Hacked UWAYS 0 276 Sep 26, 2026, 09:01 AM
Last Post: UWAYS
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 25 5,312 Sep 26, 2026, 07:08 AM
Last Post: ruroot

Forum Jump:


 Users browsing this forum: 1 Guest(s)