Skip to main content

Regarding CVE-2026-41940 server with IP-based login restrictions for WHM

Comments

3 comments

  • ITHKBO

    Hello Bidi,

    We are tracking the issue ourselves as a provider we have some issues that need clarification.
    To understand the attack I would recommend reading the proof of concept from watchtowr
    https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/

    I will preface it by saying cPanel does not condone sharing scripts on this matter so I am only linking you the lab overview. This information and the associated proofs of concepts are wildly known by now by black, red blue teams.

    To put it into as simple terms
    This vulnerability allows attackers to bypass security (IP restrictions) by using a "backdoor" trick to falsely mark themselves as already authenticated. By forcing the server to update its memory, the hacker acts as a trusted, logged-in user, making the IP restrictions irrelevant.

    This makes it very dangerous its categorised as CVSS V4 score 9.8 now and our own Dutch National Cyber Security Centre (NCSC) from Ministry of Justice has issued a custom alert on the matter. Even though this is a Dutch agency almost all information on this subject is provided in English so if you want a extensive OSINT overview of this CVE it is freely available.
    https://vulnerabilities.ncsc.nl/vulnerability.html?id=2026/cve-2026-41940

    As for timeframe we are aware of as early as February 23, 2026 verified right now from OSINT.
    https://www.reddit.com/r/cpanel/comments/1syyajp/comment/oiz12pp/
    We consider KH-DanielP (Daniel Pearson) a credible source as CEO from a reputable hostingcompany. We are in the process of contacting our security partners to run a timeline for after resolvement.

    As for accountability that is something that enters the legal terms on phrasing and you will have to read the fine prints of your contract with Webpros and talk to your legal department, team on that matter I can't provide legal advice not allowed to either. I can provide disaster recovery advice as in pointing fingers while there is a fire still going on and the situation is in mitigation and forensic cleanup phase is not recommended. That is to say; Detection & Intelligence -> Containment & Mitigation -> Forensics & Impact -> Documentation & Post-Mortem -> Accountability & Feedback

    We are personally between Containment & Mitigation -> Forensics & Impact you might be further on this trajectory that is for you to decide and we do not expect any information on that as answer back.


    @cPRex
    Because you understandably closed our forum post on CVE-2026-41940 I want to let you know we asked our datacentre partner to submit a ticket on our behalf regarding our findings as we are apparently not allowed to do so anymore directly. I asked them to mention you for tracking the ticket just in case.

    My apology to have to mention it here but I did not have any other means to do so. Unfortunately that also means that there is added delay between our communication with WebPros as I need to wait on our partner for feedback response. That is another matter which I have instructed our provider of mincing words with to webpros I am not holding you to that and I do not expect any answer on this either here this comment part is purely informational and out of courtesy.

    0
  • Bidi

    There is still no excuse that can justify this. If my colleague discovered the issue on March 17 and reported it to cPanel, and they ignored it, then cPanel should be held liable and pay damages. They were aware of the problem but did nothing.

    Legally, you cannot create terms and conditions that only protect yourself — that is not valid. And I’m sure that if someone with a good lawyer suffers damages, they could easily win a case, if it comes to that.

    Personally, I have reported many security issues in the past and was also ignored by cPanel. At some point, I stopped reporting vulnerabilities that affected everyone, not just me, because there was no response.

    From a legal standpoint, any company that provides a service must also take responsibility for it. You cannot legally say “we take your money but we are not responsible for anything” — that is simply not acceptable.

    As for me, I made up my mind about cPanel about five years ago. The only reason we still use it is because clients request it. Otherwise, we would have stopped using cPanel a long time ago. In my opinion, it has become more like a toy than a professional solution.

    0
  • cPRex Jurassic Moderator

    No legal talk allowed on the Forums - thread locked.

    0

Post is closed for comments.