Improper authentication in cPanel - CVE-2026-41940
Published: April 30, 2026 / Updated: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the authentication process. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to the application.
Successful exploitation of the vulnerability may result in full system compromise.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-41940
Links to Public Exploits and PoC-codes
- Exploit #12921 - cPanel-WHM-CVE-2026-41940-auth-bypass-exploit (Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy (August 14, 2026)
- Exploit #12772 - CVE-2026-41940-PoC (CVE-2026-41940 exploitation proof-of-concept project) (June 23, 2026)
- Exploit #12728 - CVE-2026-41940-cPanel-Auth-Bypass-Exploit () (May 22, 2026)
- Exploit #12713 - cPanel/WHM CRLF Injection Authentication Bypass RCE (May 18, 2026)
- Exploit #12710 - cve202641940 (bir cve için egitim amaçlı exploit ) (May 15, 2026)
- Exploit #12708 - CVE-2026-41940-PoC-Exploit (? CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow ? CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Adva (May 15, 2026)
- Exploit #12681 - cPanel-WHM-AuthBypass-Session-Checker (April 30, 2026)
- Exploit #12680 - CVE-2026-41940-Exploit-PoC (April 30, 2026)
- Exploit #12679 - CVE-2026-41940-MASS-EXPLOIT (April 30, 2026)