¡¾¸´ÏÖ¡¿cPanel & WHM Éí·ÝÈÏÖ¤ÈÆ¹ý·ì϶ £¨CVE-2026-41940£©

°ä²¼¹¦·ò 2026-04-30

cPanel & WHMÊÇ¿í·ºÓÃÓÚÐé¹¹Ö÷»ú¡¢¡¢¹²ÏíÖ÷»úºÍ·þÎñÆ÷Íйܻ·¾³µÄWebÖÎÀí½ÚÖÆÃæ°å£¬£¬ÆäÖÐWHMÖØÒªÃæÏò·þÎñÆ÷ÖÎÀíÔ±£¬£¬cPanelÃæÏòµ¥¸öÕ¾µã»òÍйÜÕË»§Óû§¡£¡£


CVE-2026-41940ÊÇcPanel & WHMÖеÄÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶£¬£¬ÆäÖ÷ÌâµÀÀíÊǹ¥»÷Õß¿Éͨ¹ý´«È¾Ô¤ÈÏÖ¤»á»°Îļþ£¬£¬Ê¹Î´ÈÏÖ¤»á»°±»ÃýÎóдÈëÈÏÖ¤³É¹¦×´Ì¬×ֶΣ¬£¬´Ó¶øÈƹýÕý³£µÇ¼УÑé¡£¡£


ƾ¾Ý¹¥»÷ÃæÖÎÀíÆ½Ì¨CensysµÄÊý¾Ý£¬£¬½ØÖÁ2026Äê4ÔÂ30ÈÕ£¬£¬»¥ÁªÍøÉÏ´æÔÚ2,762,782¸öDZÔÚµÄÒ×Êܹ¥»÷cPanel & WHMʵÀý¡£¡£ÓÉÓÚ¸ÅÄîÑéÖ¤·ì϶ÀûÓ÷¨Ê½ÒѾ­°ä²¼£¬£¬²¢ÇҸ÷ì϶ÒÑÔÚ»¥ÁªÍøÉÏ¿í·º´«²¼£¬£¬Òò¶ø¶ÔÓÚʹÓÃcPanel & WHMµÄ×éÖ¯¶øÑÔ£¬£¬¸Ã·ì϶×é³ÉÁËÖ±½ÓÇÒÑÏÖØµÄ·çÏÕ¡£¡£


·ì϶ÃèÊö


CVE-2026-41940·ì϶³Ê´Ë¿ÌcPanel & WHMµÄµÇ¼ÈÏÖ¤Óë»á»°´¦ÖÃÁ÷³ÌÖС£¡£Õý³£Çé¿öÏ£¬£¬Óû§½Ó¼ûWHM/cPanelµÇ¼½Ó¿Úºó£¬£¬ÏµÍ³»áΪµÇ¼Á÷³Ì´´½¨»á»°Îļþ£¬£¬ÓÃÓÚ±£ÁôÆðÔ´µØÖ·¡¢¡¢µÇ¼״̬¡¢¡¢°²È«ÁîÅÆ¡¢¡¢Ë«³É·ÖÈÏ֤״̬µÈÐÅÏ¢¡£¡£¼´±ãÓû§Ìá½»ÁËÃýÎóÃÜÂ룬£¬ÏµÍ³Ò²¿ÉÄÜÌìÉúÒ»¸öÔ¤ÈÏÖ¤»á»°£¬£¬ÓÃÓڼͼ±¾´Îʧ°ÜµÇ¼¹ý³ÌÖеÄһʱ״̬¡£¡£


·ì϶µÄ¹Ø¼üÎÊÌâÔÚÓÚ£º£º£ºÔ¤ÈÏÖ¤»á»°ÖеIJ¿ÃÅ×ֶοÉÔÚÌØ¶¨ÈÏÖ¤õ辶ϱ»Ò쳣дÈë¡£¡£ÈôÊǹ¥»÷Õß»ú¹ØÌØÊâµÄÈÏÖ¤Êý¾Ý£¬£¬Ê¹ÃÜÂë×Ö¶ÎÖÐÔ̺¬»»Ðеȷָô×Ö·û£¬£¬²¢¹²Í¬Òì³£µÄ»á»°Cookie״̬£¬£¬¾Í¿ÉÄܵ¼ÖÂÕý±¾Ó¦×÷Ϊµ¥¸ö×ֶα£ÁôµÄÄÚÈݱ»½âÎö³É¶à¸ö¶ÀÁ¢µÄ»á»°¼üÖµ¡£¡£Ëæºó£¬£¬µ±·þÎñ¶ËÖØÐ¼ÓÔØraw session²¢Ð´Èëcache sessionʱ£¬£¬ÕâЩαÔì×ֶοÉÄܱ»ÌáÉýΪ¶¥²ã»á»°ÊôÐÔ¡£¡£


µ±±»´«È¾µÄ»á»°ÖгöÏÖÈÏÖ¤³É¹¦×´Ì¬×Ö¶Îʱ£¬£¬ºóÐøÈÏÖ¤ÅжϿÉÄÜÃýÎóµØÒÔΪ¸Ã»á»°ÒѾ­ÊµÏÖÈÏÖ¤£¬£¬´Ó¶øÌø¹ýÕæÊµÃÜÂëУÑé¡£¡£¹¥»÷³É¹¦ºó£¬£¬¹¥»÷Õß¿ÉÄÜÒÔWHMÖÎÀíÉí·Ý½øÈë½ÚÖÆÃæ°å£¬£¬½øÒ»²½Ö´ÐÐÕË»§ÖÎÀí¡¢¡¢´òË㹤×÷Ö²ÈëµÈ¸ßΣ²Ù×÷¡£¡£


Ó°ÏìÁìÓò


cPanel & WHM < 11.110.0.97

cPanel & WHM < 11.118.0.63

cPanel & WHM < 11.126.0.54

cPanel & WHM < 11.130.0.19

cPanel & WHM < 11.132.0.29

cPanel & WHM < 11.134.0.20

cPanel & WHM < 11.136.0.5


·ì϶µÀÀí


¸Ã·ì϶ÐÔÖÊÉÏÊÇ¡°»á»°Îļþ×¢Èë + »á»°×´Ì¬ÌáÉý + ÈÏ֤״̬ÐÅÀµ²»µ±¡±¹²Í¬µ¼ÖµÄÈÏÖ¤ÈÆ¹ý¡£¡£


ÐÞ¸´Ç°£¬£¬saveSessionÖжÔpass×ֶεĴúÂë¿É³éÏóΪ£º£º£º


ͼƬ1.png


¸ÃÂß¼­´æÔÚÁ½¸ö¹Ø¼üÎÊÌâ¡£¡£


£¨1£©filter_sessiondata()²¢Î´Ç¿ÖÆÔÚsaveSession()ÄÚ²¿Ö´ÐУ¬£¬¶øÊÇÒÀÀµ·ÖÆçŲÓ÷½×ÔÐÐŲÓᣡ£ÈôÊÇijÌõõè¾¶Ö±½ÓŲÓÃsaveSession()£¬£¬ÇÒûÓÐÌáǰ¹ýÂË \r¡¢¡¢\n¡¢¡¢= µÈΣÏÕ×Ö·ûµ¼ÖÂsession×ֶα»´«È¾¡£¡£


£¨2£©pass×Ö¶ÎÊÇ·ñ±àÂëÈ¡¾öÓÚ$obÊÇ·ñ´æÔÚ¡£¡£$obÀ´×ԻỰCookieÖжººÅºóµÄƬ¶Î£¬£¬ÀýÈ磺£º£º


ͼƬ2.png


ÈôÊÇÒªÇóÖÐֻЯ´ø£º£º£º


ͼƬ3.png


Ôò$obΪ¿Õ£¬£¬Cpanel::Session::Encoder²»»á³õʼ»¯£¬£¬pass×Ö¶ÎÒ²²»»á±»±àÂë¡£¡£²¹¶¡ÐÂÔöÁ˶Ôfilter_sessiondata()µÄͳһŲÓ㬣¬²¢ÔÚ$obȱʧʱ½«ÃÜÂë×ֶα£ÁôΪno-ob£º£º£º¼ÓÊ®Áù½øÖƱàÂë´ó¾Ö£¬£¬Ô¤·ÀCRLFÔ­Ñù½øÈëraw session¡£¡£


Basic Authenticationõè¾¶´«È¾·ì϶´¥·¢õ辶λÓÚcpsrvd¶ÔBasic AuthenticationµÄ´¦ÖÃÂß¼­¡£¡£ÓйشúÂë¿É³éÏóΪ£º£º£º


ͼƬ4.png


ÕâÀïµÄ´àÈõµãÊÇ£º£º£º$pass À´×Ô Authorization: Basic ½âÂëºóµÄÃÜÂ벿ÃÅ£¬£¬¶ø set_pass() Ö»ÒƳý NUL ×Ö½Ú£¬£¬²»ÒƳý \r »ò \n¡£¡£Òò¶ø£¬£¬¹¥»÷ÕßÄܹ»ÈàBasic ÈÏÖ¤½âÂëÁ˾ֳöÏÖÈçϽṹ£º£º£º


ͼƬ5.png


·þÎñ¶ËÒÀÈ»ÒÔΪx\r\n... ÊÇpass×ֶεÄÖµ£¬£¬µ«µ±Ëü±»Ð´Èëraw sessionÎļþºó£¬£¬Îı¾Îļþ»áÔì³É¶àÐÐkey=value½á¹¹¡£¡£¸Ãõè¾¶»áÖ±½ÓŲÓÃsaveSession()£¬£¬²¢ÇÒ$passÖеÄCRLF»á±»Ð´Èë /var/cpanel/sessions/raw/¡£¡£


·ì϶¸´ÏÖ


£¨1£©WHMÊ×Ò³ÈçÏ£º£º£º


ͼƬ6.png


£¨2£©Ö´ÐÐPOC²é¿´ËùÓÐÕ˺ÅÐÅÏ¢


ͼƬ7.png


°²È«½¨Òé


    £¨1£©Á¢¼´Éý¼¶

    cPanel¹Ù·½ÒѰ䲼°²È«²¼¸æ£¬£¬Çë°´Áìµ¼½øÐÐÐÞ¸´¡£¡£


    £¨2£©Ò»Ê±»º½â´ëÊ©

    ? ÈôÁÙʱÎÞ·¨Éý¼¶£¬£¬¿ÉÔÚ·À»ðǽÉÏ×èÖ¹¶Ë¿Ú2083¡¢¡¢2087¡¢¡¢2095ºÍ2096µÄÈëÕ¾Á÷Á¿¡£¡£

    ? »òһʱͣÓÃÓйطþÎñ¡£¡£

    ͼƬ8.png



    ²Î¿¼Á´½Ó£º£º£º

    [1]https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026



    OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


    ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£¡£½ØÖÁĿǰ£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑС¢¡¢µçÐÅÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑС¢¡¢Òƶ¯Öն˰²È«×êÑС¢¡¢Ôư²È«×êÑС¢¡¢ÐÅ´´°²È«×êÑС¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢³µÁªÍø°²È«×êÑС¢¡¢¹¤¿Ø°²È«×êÑС¢¡¢Êý¾Ý°²È«×êÑС¢¡¢5G°²È«×êÑС¢¡¢AI°²È«×êÑС¢¡¢ÎÀÐǰ²È«×êÑС¢¡¢µÍ¿Õ°²È«×êÑС¢¡¢¸ß¼¶Íþв×êÑС¢¡¢¹¥·Àϵͳ½¨Éè¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£


    adlab.jpg