Regarding CVE-2026-41940 server with IP-based login restrictions for WHM
Hello guys,
I just don’t understand how a server with IP-based login restrictions for WHM/cPanel/SSH, etc., could have been compromised. This makes me think it might be an internal issue within cPanel itself.
Also, this security bypass issue has existed since March 17, not since April 28. One of my colleagues noticed it on a cPanel testing server, and we were even able to see what had been done on that server. As far as I understand, this was already reported to cPanel, but no action was taken until multiple affected servers were reported.
Who is going to pay for this? Data loss, compromised servers, companies having to reinstall systems, all the work involved, downtime, etc. In my opinion, cPanel should be held responsible for this. Yes, I know you’ll say companies should have backups — and that’s true — but what about the time, effort, and downtime required to rebuild servers and websites?
If I make a mistake, I am held accountable and I pay for it. Why should it be different here?
How come nobody is talking about this? I haven’t found any discussions about it. Is this being ignored or hidden?
-
Hello Bidi,
We are tracking the issue ourselves as a provider we have some issues that need clarification.
To understand the attack I would recommend reading the proof of concept from watchtowr
https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/I will preface it by saying cPanel does not condone sharing scripts on this matter so I am only linking you the lab overview. This information and the associated proofs of concepts are wildly known by now by black, red blue teams.
To put it into as simple terms
This vulnerability allows attackers to bypass security (IP restrictions) by using a "backdoor" trick to falsely mark themselves as already authenticated. By forcing the server to update its memory, the hacker acts as a trusted, logged-in user, making the IP restrictions irrelevant.This makes it very dangerous its categorised as CVSS V4 score 9.8 now and our own Dutch National Cyber Security Centre (NCSC) from Ministry of Justice has issued a custom alert on the matter. Even though this is a Dutch agency almost all information on this subject is provided in English so if you want a extensive OSINT overview of this CVE it is freely available.
https://vulnerabilities.ncsc.nl/vulnerability.html?id=2026/cve-2026-41940
As for timeframe we are aware of as early as February 23, 2026 verified right now from OSINT.
https://www.reddit.com/r/cpanel/comments/1syyajp/comment/oiz12pp/
We consider KH-DanielP (Daniel Pearson) a credible source as CEO from a reputable hostingcompany. We are in the process of contacting our security partners to run a timeline for after resolvement.As for accountability that is something that enters the legal terms on phrasing and you will have to read the fine prints of your contract with Webpros and talk to your legal department, team on that matter I can't provide legal advice not allowed to either. I can provide disaster recovery advice as in pointing fingers while there is a fire still going on and the situation is in mitigation and forensic cleanup phase is not recommended. That is to say; Detection & Intelligence -> Containment & Mitigation -> Forensics & Impact -> Documentation & Post-Mortem -> Accountability & Feedback
We are personally between Containment & Mitigation -> Forensics & Impact you might be further on this trajectory that is for you to decide and we do not expect any information on that as answer back.
@cPRex
Because you understandably closed our forum post on CVE-2026-41940 I want to let you know we asked our datacentre partner to submit a ticket on our behalf regarding our findings as we are apparently not allowed to do so anymore directly. I asked them to mention you for tracking the ticket just in case.My apology to have to mention it here but I did not have any other means to do so. Unfortunately that also means that there is added delay between our communication with WebPros as I need to wait on our partner for feedback response. That is another matter which I have instructed our provider of mincing words with to webpros I am not holding you to that and I do not expect any answer on this either here this comment part is purely informational and out of courtesy.
0 -
There is still no excuse that can justify this. If my colleague discovered the issue on March 17 and reported it to cPanel, and they ignored it, then cPanel should be held liable and pay damages. They were aware of the problem but did nothing.
Legally, you cannot create terms and conditions that only protect yourself — that is not valid. And I’m sure that if someone with a good lawyer suffers damages, they could easily win a case, if it comes to that.
Personally, I have reported many security issues in the past and was also ignored by cPanel. At some point, I stopped reporting vulnerabilities that affected everyone, not just me, because there was no response.
From a legal standpoint, any company that provides a service must also take responsibility for it. You cannot legally say “we take your money but we are not responsible for anything” — that is simply not acceptable.
As for me, I made up my mind about cPanel about five years ago. The only reason we still use it is because clients request it. Otherwise, we would have stopped using cPanel a long time ago. In my opinion, it has become more like a toy than a professional solution.
0 -
No legal talk allowed on the Forums - thread locked.
0
Post is closed for comments.
Comments
3 comments