cPanel and WHM Hit by CVE-2026-41940 Authentication Bypass, Threat Actor Mr_Rot13 Deploys Filemanager Backdoor
Patch cPanel to the latest release that addresses CVE‑2026‑41940 immediately.
Patch cPanel to the latest release that addresses CVE‑2026‑41940 immediately.
Summary
cPanel and WebHost Manager (WHM) have been hit by a critical authentication bypass flaw, CVE‑2026‑41940, that allows remote attackers to gain elevated control over the control panel. The vulnerability was first reported on 9 April 2026 and was exploited by the threat actor Mr_Rot13, who deployed a backdoor named Filemanager on compromised systems. The flaw permits an unauthenticated attacker to bypass login checks and execute arbitrary commands with root privileges. cPanel has released a patch in the latest stable release that validates credentials and enforces proper session handling. Users should immediately update to the patched version to prevent further exploitation. The advisory also recommends disabling unused modules and monitoring for suspicious file modifications. The incident highlights the need for strict access controls and timely application of security updates for shared hosting environments.
The backdoor Filemanager provides a web-based interface that allows attackers to upload malicious files, modify configuration, and exfiltrate data. cPanel’s response includes a detailed technical explanation of the bypass and the steps to remediate. Hosting providers should audit their WHM installations for signs of compromise and apply the patch before the threat actor can expand its foothold. The advisory stresses that the vulnerability is not limited to a single cPanel version, affecting all releases prior to the patch.
Key changes
- CVE‑2026‑41940 is an authentication bypass flaw in cPanel and WHM.
- The flaw allows unauthenticated attackers to gain elevated control and execute arbitrary commands.
- Threat actor Mr_Rot13 exploited the vulnerability to deploy a backdoor named Filemanager.
- The backdoor provides a web interface for uploading malicious files and modifying configuration.
- cPanel released a patch in the latest stable release that validates credentials and enforces session handling.
- Users must update to the patched version immediately to prevent exploitation.
- The vulnerability affects all cPanel releases prior to the patch.
- The advisory recommends disabling unused modules and monitoring for suspicious file modifications.