The author of the ctdal repository says their PoC for CVE-2026-41940 lets an unauthenticated attacker gain root-level access in WHM without credentials. A PoC is a proof of concept for reproducing a vulnerability.

According to the author, this is a critical authentication bypass in cPanel & WHM with a CVSS score of 10.0. The README lists vulnerable and patched versions for six cPanel & WHM branches, from 110.x through 136.x.

Claim check:

  • The author of the ctdal repository says their PoC for CVE-2026-41940 lets an unauthenticated attacker gain root-level access in WHM without credentials. (confirmed by the publication itself: evidence; «A tool for exploiting CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0), allowing unauthenticated attackers to gain root-level WHM access by injecting CRLF sequences into server-side session files via the Authorization header — no credentials required.»)
  • According to the author, this is a critical authentication bypass in cPanel & WHM with a CVSS score of 10.0. (confirmed by the publication itself: evidence; «A tool for exploiting CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0), allowing unauthenticated attackers to gain root-level WHM access by injecting CRLF sequences into server-side session files via the Authorization header — no credentials required.»)
  • The README lists vulnerable and patched versions for six cPanel & WHM branches, from 110.x through 136.x. (confirmed by the publication itself: evidence; «110.x ≤ 11.110.0.96 11.110.0.97 118.x ≤ 11.118.0.62 11.118.0.63 126.x ≤ 11.126.0.53 11.126.0.54 132.x ≤ 11.132.0.28 11.132.0.29 134.x ≤ 11.134.0.19 11.134.0.20 136.x ≤ 11.136.0.4 11.136.0.5»)

Primary sources:

score 71.4 out of 100 · kind: incident