cPanel & WHM 权限绕过漏洞(CVE-2026-41940)

2026-04-30 cPanel & WHM PoC Public

Description

cPanel & WHM 是 cPanel, LLC. 开发的 Web 主机控制面板解决方案,WHM 是服务器管理界面,cPanel 是用户面板,该产品管理着全球超过 7000 万个域名,是共享托管基础设施的核心组件。cPanel & WHM 在会话处理过程中存在权限绕过漏洞,未经身份验证的攻击者可通过 CRLF 注入操作会话文件,将预认证会话提升为 root 权限会话,从而获取服务器完整管理权限。

PoC

https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities