cPanel & WHM - Authentication Bypass via Session-File CRLF Injection CVE-2026-41940

Detectable with
Network Scanner
Scan engine
Nuclei
Cisa Kev
Cybersecurity Infrastructure Security Agency (CISA) Yes
Exploitable with Sniper
No
CVE Published
Apr 29, 2026
Detection added at
Software Type
Not available
Vendor
Not available
Product
Not available

Detect & validate this vulnerability

Go beyond surface scans. Get real validation with proprietary tools designed to prove what’s exploitable in your environment.