PT-2026-35936 · WordPress+1 · Wp Squared+1

·

CVE-2026-41940

·

Published

2026-04-29

·

Updated

2026-07-31

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cPanel versions prior to 11.86.0.41 cPanel versions prior to 11.110.0.97 cPanel versions prior to 11.118.0.63 cPanel versions prior to 11.124.0.35 cPanel versions prior to 11.126.0.54 cPanel versions prior to 11.130.0.19 cPanel versions prior to 11.132.0.29 cPanel versions prior to 11.134.0.20 cPanel versions prior to 11.136.0.5 WebHost Manager (WHM) versions prior to 11.136.0.5 WP Squared versions prior to 136.1.7
Description A critical authentication bypass exists in the cpsrvd service daemon of cPanel and WHM. The issue stems from improper sanitization of the Authorization header during the pre-authentication session creation flow. An attacker can use a CRLF (Carriage Return Line Feed) injection attack by sending specially crafted r characters in the Authorization header. This allows the attacker to terminate legitimate data fields in the temporary session file and inject arbitrary properties, such as user=root or hasroot=1. By subsequently triggering a session reload—often by sending a GET request lacking a security token—the system reads these injected values as valid, granting the attacker full administrative root access without a password.
Approximately 1.5 to 2 million instances are estimated to be exposed worldwide. The flaw has been exploited in the wild since February 2026 by various actors, including the Sorry ransomware group and the Mr Rot13 threat actor. Exploitation has led to the deployment of the Sorry ransomware (written in Golang), the installation of the Filemanager backdoor, and the deployment of PHP webshells. Attackers have also used this access to exfiltrate credentials via Telegram and propagate through local SSH connections using brute-force attacks.
Recommendations Update cPanel and WHM to versions 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.124.0.35, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, or 11.136.0.5. Update WP Squared to version 136.1.7 or later. As a temporary mitigation, block inbound traffic on ports 2082, 2083, 2086, 2087, 2095, and 2096 at the edge firewall. Restrict access to the WHM management plane to trusted static IP addresses or VPN ranges only. Temporarily stop the cpsrvd and cpdavd services if immediate patching is not possible.

Exploit

Fix

RCE

DoS

LPE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06279
CVE-2026-41940

Affected Products

Wp Squared
Cpanel & Whm