CVE-2026-41940: cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
HoneyLabs honeypots recorded 54 probes matching CVE-2026-41940 from 27 distinct source IP addresses in the last 7 days. Severity is rated CRITICAL.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /login/?login_only=1
- /json-api/version
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 103.252.221.157 | 9 | Hostpalace Datacenters Ltd | Italy |
| 47.251.42.6 | 6 | Alibaba (US) Technology Co., Ltd. | United States |
| 45.198.224.26 | 6 | Vpsvault.host Ltd | United States |
| 50.116.72.42 | 3 | Network Solutions, LLC | United States |
| 68.178.167.214 | 3 | GoDaddy.com, LLC | United States |
| 20.193.146.159 | 3 | Microsoft Corporation | India |
| 57.159.30.22 | 2 | Microsoft Corporation | India |
| 40.81.230.77 | 2 | Microsoft Corporation | India |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS8075 | Microsoft Corporation | 19 | 14 |
| AS60064 | Hostpalace Datacenters Ltd | 9 | 1 |
| AS45102 | Alibaba (US) Technology Co., Ltd. | 6 | 1 |
| AS215925 | Vpsvault.host Ltd | 6 | 1 |
| AS19871 | Network Solutions, LLC | 3 | 1 |
| AS26496 | GoDaddy.com, LLC | 3 | 1 |
Captured requests
- /login/?login_only=1
HTTP client fingerprints (JA4H)
- po11nn0600_f8bf768a441b
- po11nn0500_b4ba55311b46
- po11nn0700_fb204b7f5765
CVE report
CVE report
Open a specific CVE from the CVE tracker.