PoC Archive PoC Archive

tag

WHM

  • CVE-2026-54420 network HIGH 8.5 KEV

    LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420

    LiteSpeed's cPanel and WHM plugins mishandle user-supplied symbolic links on shared hosting servers isolated with CloudLinux/CageFS. A tenant with FTP or web shell access to their own account can create a symlink (via SITE SYMLINK, rename-based tricks, or…

    Unverified 2026-07-05
  • CVE-2026-41940 web CRITICAL 10 KEV Ransomware EPSS 98%

    cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)

    CVE-2026-41940 is a critical unauthenticated authentication bypass in cPanel & WHM. The vulnerable session handling flow writes attacker-controlled Authorization: Basic data to the session file before sanitization, allowing CRLF injection of trusted session…

    Patched 2026-05-16