Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


saf

saf

241 posts

Master Geek
+1 received by user: 595

ID Verified
Trusted
Vetta Group
Subscriber

#324602 2-May-2026 22:36
Send private message quote this post

If you’re running cPanel/WHM and haven’t patched yet, stop what you’re doing.

 

We’ve just finished assisting with a restoration on a server that was hit by this (not one of our boxes) - and it’s as bad as it sounds. Full root-level compromise, web shells dropped, the works.

 

Quick summary for those who haven’t seen it yet: CVE-2026-41940 is a pre-authentication CRLF injection in cpsrvd that lets an attacker inject arbitrary properties into a session file before any credential check occurs - effectively granting themselves root WHM access with a single crafted HTTP request. CVSS 9.8, no privileges required, no user interaction, remotely exploitable. A public PoC has been out since April 29 and Shadowserver was seeing ~44K IPs actively scanning within 24 hours of disclosure. CISA added it to the KEV catalog same day.

 

Affects all cPanel/WHM versions after v11.40. Patches dropped April 28 - update to your track’s fixed version and restart cpsrvd.

 

If you patched after the vulnerability was already being exploited (in the wild since at least February 23), treat the server as compromised and investigate - don’t just patch and move on.

 

We’ve written up a full breakdown including the exploit chain, CVSS breakdown, IoCs to look for, and the disclosure timeline here: https://vetta.nz/cve-2026-41940-critical-authentication-bypass-in-cpanel-and-whm/ - hopefully this is helpful!

 

TL;DR: If you work with, or on, cPanel servers - check and do the thing right now!





My views are as unique as a unicorn riding a unicycle. They do not reflect the opinions of my employer, my cat, or the sentient coffee machine in the break room.


Create new topic
Quinny
936 posts

Ultimate Geek
+1 received by user: 212

Trusted

  #3487304 4-May-2026 12:36
Send private message quote this post

Great article. Really explains well. Our ISP was affected and while we are sorting stuff like new passwords and cpanel access today nothing got encripted.  




nztim
4099 posts

Uber Geek
+1 received by user: 2809

ID Verified
Trusted
TEAMnetwork
Subscriber

  #3487309 4-May-2026 12:58
Send private message quote this post

CVE-2026-31431 just come out too allowing to you root any Linux box since 2017

 

I have not read up enough on the attack vectors yet.....





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


saf

saf

241 posts

Master Geek
+1 received by user: 595

ID Verified
Trusted
Vetta Group
Subscriber

  #3487312 4-May-2026 13:02
Send private message quote this post

Quinny:

 

Great article. Really explains well. Our ISP was affected and while we are sorting stuff like new passwords and cpanel access today nothing got encripted.  

 

 

Thank you! Great to hear your ISP were also on the case.

 

 

 

nztim:

 

CVE-2026-31431 just come out too allowing to you root any Linux box since 2017

 

I have not read up enough on the attack vectors yet.....

 

 

Yep, also nasty - however at least Copy Fail requires a local account with escalation from an unprivileged user, whereas this one is walking in the door on a web port usually publicly exposed on cPanel servers... Nasty.

 

We're in the middle of doing an article on Copy Fail too, should be up later today or tomorrow.





My views are as unique as a unicorn riding a unicycle. They do not reflect the opinions of my employer, my cat, or the sentient coffee machine in the break room.




nztim
4099 posts

Uber Geek
+1 received by user: 2809

ID Verified
Trusted
TEAMnetwork
Subscriber

  #3487315 4-May-2026 13:11
Send private message quote this post

saf:

 

Yep, also nasty - however at least Copy Fail requires a local account with escalation from an unprivileged user

 

 

How many arg gis users are on Linux desktops and maybe disgruntled employees and decide to root their boxes and slip themselves into the SUDO group for a later date

 

it's pretty bad stuff





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


saf

saf

241 posts

Master Geek
+1 received by user: 595

ID Verified
Trusted
Vetta Group
Subscriber

  #3487335 4-May-2026 13:53
Send private message quote this post

nztim:

 

How many arg gis users are on Linux desktops and maybe disgruntled employees and decide to root their boxes and slip themselves into the SUDO group for a later date

 

it's pretty bad stuff

 

 

Yep, absolutely!





My views are as unique as a unicorn riding a unicycle. They do not reflect the opinions of my employer, my cat, or the sentient coffee machine in the break room.


zaptor
746 posts

Ultimate Geek
+1 received by user: 40


  #3487629 5-May-2026 11:43
Send private message quote this post

saf:

 

We’ve written up a full breakdown including the exploit chain, CVSS breakdown, IoCs to look for, and the disclosure timeline here: https://vetta.nz/cve-2026-41940-critical-authentication-bypass-in-cpanel-and-whm/ - hopefully this is helpful!

 

 

Great write up - thank you.

 

The email provider for a non-profit I help with got hit. So that info, and the subsequent rabbit warren I went down was excellent.

 

Especially the reference to watchtowr - excellent writeup of the issue, who even provide a PoV on their GitHub.


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
alexx
873 posts

Ultimate Geek
+1 received by user: 304

Lifetime subscriber

  #3491309 15-May-2026 21:49
Send private message quote this post

nztim:

 

CVE-2026-31431 just come out too allowing to you root any Linux box since 2017

 

I have not read up enough on the attack vectors yet.....

 

 

There are proof of concept exploits that run from command line for CVE-2026-31431 a.k.a  "Copy Fail" and allow any user to get root.

 

https://copy.fail/

 

Plus there are these two which together go by the name of "Dirty Frag" and also allow any command line user to get root.

 

     

  • xfrm-ESP Page-Cache Write (CVE-2026-43284)
  • RxRPC Page-Cache Write (CVE-2026-43500)

More info here: https://github.com/V4bel/dirtyfrag 





#include <standard.disclaimer>


Create new topic




News and reviews »

Philips Hue Ultra-Bright LED Strip Flux Review
Posted 29-Jun-2026 10:46


ECOVACS Deebot T80s Review
Posted 22-Jun-2026 11:58


D-Link A/NZ Launches GaN Charger Range
Posted 12-Jun-2026 09:25


New Amazon Kindle Scribe Range Now Available in New Zealand
Posted 12-Jun-2026 09:19


OPPO Watch X3 Launches in New Zealand
Posted 5-Jun-2026 17:01


Blink Debuts Its First 2K Video Doorbell
Posted 4-Jun-2026 15:45






Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.