S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 29, 2026

CVE-2026-41940 Scanner

CVE-2026-41940 Scanner - CRLF Injection vulnerability in cPanel & WHM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-41940
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cPanelby WebPros
AFFECTED< 11.86.0.41SAFE ✓≥ 11.86.0.41
WP Squaredby WebPros
11.136.1.7
WHMby WebPros
AFFECTED< 11.86.0.41SAFE ✓≥ 11.86.0.41
Updated Sep 10, 2026View on NVD →
Detail

cPanel & WHM is widely used software by web hosting companies to manage web hosting servers and accounts. It provides a graphical interface and automation tools designed to simplify the process of hosting a web site. Administrators use it to manage domains, implement security measures, and automate tasks through its control panel. Given its extensive functionality, cPanel & WHM is a popular choice for server management in many enterprise and small-scale businesses. Applications using cPanel & WHM facilitate easy management tasks, enhancing server administration efficiency. Often, this software is employed for managing multiple hosting accounts and setting up web hosting environments systematically.

The CRLF Injection vulnerability detected in cPanel & WHM allows unauthorized access to the control panel by manipulating the login session. This vulnerability occurs when carriage return and line feed (CRLF) sequences are improperly filtered, enabling attackers to inject unauthorized responses. Exploitation of this issue can lead to unauthorized control over the cPanel system, allowing attackers to bypass authentication mechanisms. Such vulnerabilities can compromise the security structure, potentially leading to significant issues such as data breaches. The vulnerability primarily affects the login flow, contributing to an authentication bypass issue. Proper mitigation requires updates to the later versions of the software.

Technically, this vulnerability involves the manipulation of session file headers through CRLF sequences which lead to authentication bypass. The vulnerability allows the attacker to modify HTTP headers and potentially inject harmful directives. This is done by exploiting specific endpoints in the HTTP request flow during login attempts. The attacker can manipulate header fields that should not normally be accessible or altered, leading to unauthorized access. Automation handling in the login scripts is disrupted due to this improper handling of CRLF sequences. It is identified by observing unauthorized redirect behavior and unsanctioned session management through the HTTP flow. Specifically, this vulnerability exists before authorization and can have a wide-reaching impact on server control and management if not addressed.

The exploitation of this vulnerability can lead to severe consequences due to the potential control over the hosting server. Intrusions can cause unwanted access to sensitive information, leading to data theft and unauthorized data manipulation. Attackers could gain control over server management functions, allowing changes in DNS settings, email configurations and potentially installing malicious software. This might also lead to distributed denial of service (DDoS) attacks initiated through compromised cPanel management interfaces. Overall, the exploitation can severely degrade service integrity and availability, implicating its users. Recovery and forensic investigation could be significantly complicated following an attack exploiting this vulnerability.

REFERENCES

Solution Advice
  • Upgrade cPanel & WHM to version 11.136.0.5 or later to mitigate this vulnerability.
  • Implement consistent session management practices to ensure session integrity.
  • Regularly audit server logs to detect any unauthorized access attempts or irregular activity.
  • Enable additional layers of user authentication to provide enhanced security measures.
  • Monitor security advisories for upcoming patches related to similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.