PT-2026-35936 · WordPress+1 · Wp Squared+1
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cPanel versions prior to 11.86.0.41
cPanel versions prior to 11.110.0.97
cPanel versions prior to 11.118.0.63
cPanel versions prior to 11.124.0.35
cPanel versions prior to 11.126.0.54
cPanel versions prior to 11.130.0.19
cPanel versions prior to 11.132.0.29
cPanel versions prior to 11.134.0.20
cPanel versions prior to 11.136.0.5
WebHost Manager (WHM) versions prior to 11.136.0.5
WP Squared versions prior to 136.1.7
Description
A critical authentication bypass exists in the
cpsrvd service daemon of cPanel and WHM. The issue stems from improper sanitization of the Authorization header during the pre-authentication session creation flow. An attacker can use a CRLF (Carriage Return Line Feed) injection attack by sending specially crafted r characters in the Authorization header. This allows the attacker to terminate legitimate data fields in the temporary session file and inject arbitrary properties, such as user=root or hasroot=1. By subsequently triggering a session reload—often by sending a GET request lacking a security token—the system reads these injected values as valid, granting the attacker full administrative root access without a password.Approximately 1.5 to 2 million instances are estimated to be exposed worldwide. The flaw has been exploited in the wild since February 2026 by various actors, including the Sorry ransomware group and the Mr Rot13 threat actor. Exploitation has led to the deployment of the Sorry ransomware (written in Golang), the installation of the Filemanager backdoor, and the deployment of PHP webshells. Attackers have also used this access to exfiltrate credentials via Telegram and propagate through local SSH connections using brute-force attacks.
Recommendations
Update cPanel and WHM to versions 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.124.0.35, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, or 11.136.0.5.
Update WP Squared to version 136.1.7 or later.
As a temporary mitigation, block inbound traffic on ports 2082, 2083, 2086, 2087, 2095, and 2096 at the edge firewall.
Restrict access to the WHM management plane to trusted static IP addresses or VPN ranges only.
Temporarily stop the
cpsrvd and cpdavd services if immediate patching is not possible.Exploit
Fix
RCE
DoS
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Squared
Cpanel & Whm