Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilityidentity-authentication-vulnerabilityproof-of-concept-releaseinternet-facing-service-vulnerability

cPanel Authentication Bypass and New RCE Flaws Put Hosting Servers at Risk

Updated 14d agoFirst seen May 10, 20266 sources

cPanel disclosed and patched a critical authentication bypass in cPanel & WHM, tracked as CVE-2026-41940, after reports of active in-the-wild exploitation against hosting infrastructure. The flaw affects authentication paths in supported versions and can let unauthenticated attackers reach administrative interfaces, forge authenticated sessions, and potentially gain control of hosted websites, databases, email accounts, and server configuration. Government and industry alerts warned that shared hosting environments face outsized risk because a single compromised server can expose many downstream customer sites, and some providers temporarily restricted cPanel and WHM login ports while applying fixes.

Public technical analysis and a GitHub proof-of-concept described an exploit chain involving manipulated HTTP headers and session cookie handling to create forged privileged sessions, including possible root-level WHM access. Separately, cPanel also patched three additional vulnerabilities in cPanel & WHM and WP SquaredCVE-2026-29201, CVE-2026-29202, and CVE-2026-29203—that enable arbitrary file read through path traversal, Perl code injection leading to remote code execution, and denial-of-service via unsafe symlink handling. The most severe of the newly disclosed flaws, CVE-2026-29202, affects the create_user API and can allow arbitrary Perl code execution on the server, reinforcing calls for immediate upgrades, restricted access to management interfaces, and log review for suspicious authorization and cookie activity.

Share:
cPanel Authentication Bypass and New RCE Flaws Put Hosting Servers at Risk
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 10, 20261mo ago

cPanel urges admins to upgrade after disclosure of new critical flaws

After patching the May vulnerabilities, cPanel advised administrators to upgrade immediately to fixed releases across supported branches, including WP Squared 11.136.1.10 or later. The company highlighted the risk of lateral movement, privilege escalation, and full server compromise in shared hosting environments.

May 8, 20261mo ago

cPanel patches three new flaws in cPanel & WHM and WP Squared

On May 8, 2026, cPanel patched three additional vulnerabilities: CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The issues enabled arbitrary file read via path traversal, Perl code injection leading to remote code execution, and denial of service through unsafe symlink handling.

May 1, 20261mo ago

Exploit framework for CVE-2026-41940 appears on GitHub

A GitHub repository named cPanelSniper was published describing and automating exploitation of CVE-2026-41940. The project outlined a session-file CRLF injection technique to obtain forged WHM access and included post-exploitation capabilities.

Apr 29, 20261mo ago

Public technical analysis details the CVE-2026-41940 bypass chain

Public analysis from watchTowr described an authentication bypass chain involving insufficient sanitization of HTTP headers and insufficient validation of session cookies. The write-up explained how forged authenticated sessions could be created against vulnerable cPanel & WHM instances.

Hosting providers temporarily block cPanel/WHM login ports

Following disclosure of CVE-2026-41940, major hosting providers including Namecheap and KnownHost temporarily blocked cPanel and WHM login ports until patches could be applied. This was a defensive response to ongoing exploitation risk.

Active exploitation of CVE-2026-41940 reported in the wild

Security reporting stated that CVE-2026-41940 was being actively exploited as a 0-day against hosting infrastructure in April 2026. Because cPanel is widely used in shared hosting, successful exploitation could expose many downstream customer sites on a single server.

Authorities warn CVE-2026-41940 is highly likely to be exploited

On April 29, 2026, the Canadian Centre for Cyber Security issued Alert AL26-008 warning that exploitation of CVE-2026-41940 was highly probable. The alert urged immediate patching, restricting access to management interfaces, and reviewing logs for suspicious activity.

cPanel discloses CVE-2026-41940 and releases emergency patches

cPanel disclosed the critical authentication bypass vulnerability CVE-2026-41940 affecting supported cPanel & WHM versions and released patched versions at disclosure. The flaw could allow unauthenticated attackers to access administrative interfaces and compromise hosted websites, databases, email accounts, and server settings.

Apr 1, 20262mo ago

CentOS Web Panel RCE advisory published

A separate advisory about remote code execution in CentOS Web Panel (CVE-2025-70951) was published by Fenrisk. It is unrelated to the cPanel/WHM vulnerabilities and does not materially advance this story.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

cPanel Authentication Bypass and New RCE Flaws Put Hosting Servers at Risk | Mallory