¡¾¸´ÏÖ¡¿cPanel & WHM Éí·ÝÈÏÖ¤ÈÆ¹ý·ì϶ £¨CVE-2026-41940£©

°ä²¼¹¦·ò 2026-04-30

cPanel & WHMÊÇ¿í·ºÓÃÓÚÐé¹¹Ö÷»ú¡¢¹²ÏíÖ÷»úºÍ·þÎñÆ÷Íйܻ·¾³µÄWebÖÎÀí½ÚÔìÃæ°å£¬ÆäÖÐWHMÖØÒªÃæÏò·þÎñÆ÷ÖÎÀíÔ±£¬cPanelÃæÏòµ¥¸öÕ¾µã»òÍйÜÕË»§Óû§¡£


CVE-2026-41940ÊÇcPanel & WHMÖеÄÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶£¬ÆäÖ÷ÌâµÀÀíÊǹ¥»÷Õß¿Éͨ¹ý´«È¾Ô¤ÈÏÖ¤»á»°Îļþ£¬Ê¹Î´ÈÏÖ¤»á»°±»ÃýÎóдÈëÈÏÖ¤³É¹¦×´Ì¬×ֶΣ¬´Ó¶øÈƹýÕý³£µÇ¼УÑé¡£


ƾ¾Ý¹¥»÷ÃæÖÎÀíÆ½Ì¨CensysµÄÊý¾Ý£¬½ØÖÁ2026Äê4ÔÂ30ÈÕ£¬»¥ÁªÍøÉÏ´æÔÚ2,762,782¸öDZÔÚµÄÒ×Êܹ¥»÷cPanel & WHMÊ·ý¡£ÓÉÓÚ¸ÅÏëÑéÖ¤·ì϶ÀûÓ÷¨Ê½ÒѾ­°ä²¼£¬²¢ÇҸ÷ì϶ÒÑÔÚ»¥ÁªÍøÉÏ¿í·º´«²¼£¬Òò¶ø¶ÔÓÚʹÓÃcPanel & WHMµÄ×éÖ¯¶øÑÔ£¬¸Ã·ì϶×é³ÉÁËÖ±½ÓÇÒÑϳÁµÄ·çÏÕ¡£


·ìϼûèÊö


CVE-2026-41940·ì϶³Ê´Ë¿ÌcPanel & WHMµÄµÇ¼ÈÏÖ¤Óë»á»°´¦ÖÃÁ÷³ÌÖС£Õý³£Çé¿öÏ£¬Óû§½Ó¼ûWHM/cPanelµÇ¼½Ó¿Úºó£¬ÏµÍ³»áΪµÇ¼Á÷³Ì´´½¨»á»°Îļþ£¬ÓÃÓÚ±£ÁôÆðÔ´µØÖ·¡¢µÇ¼״̬¡¢°²È«ÁîÅÆ¡¢Ë«³É·ÖÈÏ֤״̬µÈÐÅÏ¢¡£¼´±ãÓû§Ìá½»ÁËÃýÎóÃÜÂ룬ϵͳҲ¿ÉÄÜÌìÉúÒ»¸öÔ¤ÈÏÖ¤»á»°£¬ÓÃÓڼͼ±¾´Îʧ°ÜµÇ¼¹ý³ÌÖеÄһʱ״̬¡£


·ì϶µÄ¹Ø¼üÎÊÌâÔÚÓÚ£ºÔ¤ÈÏÖ¤»á»°ÖеIJ¿ÃÅ×ֶοÉÔÚÌØ¶¨ÈÏÖ¤õ辶ϱ»Ò쳣дÈë¡£ÈôÊǹ¥»÷Õß»ú¹ØÌØÊâµÄÈÏÖ¤Êý¾Ý£¬Ê¹ÃÜÂë×Ö¶ÎÖÐÔ̺¬»»Ðеȷָô×Ö·û£¬²¢¹²Í¬Òì³£µÄ»á»°Cookie״̬£¬¾Í¿ÉÄܵ¼ÖÂÕý±¾Ó¦×÷Ϊµ¥¸ö×ֶα£ÁôµÄÄÚÈݱ»½âÎö³É¶à¸ö¶ÀÁ¢µÄ»á»°¼üÖµ¡£Ëæºó£¬µ±·þÎñ¶Ë³ÁмÓÔØraw session²¢Ð´Èëcache sessionʱ£¬ÕâЩαÔì×ֶοÉÄܱ»ÌáÉýΪ¶¥²ã»á»°ÊôÐÔ¡£


µ±±»´«È¾µÄ»á»°ÖгöÏÖÈÏÖ¤³É¹¦×´Ì¬×Ö¶Îʱ£¬ºóÐøÈÏÖ¤ÅжϿÉÄÜÃýÎóµØÒÔΪ¸Ã»á»°ÒѾ­ÊµÏÖÈÏÖ¤£¬´Ó¶øÌø¹ýÕæÊµÃÜÂëУÑé¡£¹¥»÷³É¹¦ºó£¬¹¥»÷Õß¿ÉÄÜÒÔWHMÖÎÀíÉí·Ý½øÈë½ÚÔìÃæ°å£¬½øÒ»²½Ö´ÐÐÕË»§ÖÎÀí¡¢´òË㹤×÷Ö²ÈëµÈ¸ßΣ²Ù×÷¡£


Ó°ÏìÁìÓò


cPanel & WHM < 11.110.0.97

cPanel & WHM < 11.118.0.63

cPanel & WHM < 11.126.0.54

cPanel & WHM < 11.130.0.19

cPanel & WHM < 11.132.0.29

cPanel & WHM < 11.134.0.20

cPanel & WHM < 11.136.0.5


·ì϶µÀÀí


¸Ã·ì϶ÐÔÖÊÉÏÊÇ¡°»á»°Îļþ×¢Èë + »á»°×´Ì¬ÌáÉý + ÈÏ֤״̬ÐÅÀµ²»µ±¡±¹²Í¬µ¼ÖµÄÈÏÖ¤ÈÆ¹ý¡£


½¨¸´Ç°£¬saveSessionÖжÔpass×ֶεĴúÂë¿É³éÏóΪ£º


ͼƬ1.png


¸ÃÂß¼­´æÔÚÁ½¸ö¹Ø¼üÎÊÌâ¡£


£¨1£©filter_sessiondata()²¢Î´Ç¿ÔìÔÚsaveSession()ÄÚ²¿Ö´ÐУ¬¶øÊÇÒÀÀµ·ÖÆçŲÓ÷½×ÔÐÐŲÓá£ÈôÊÇijÌõõè¾¶Ö±½ÓŲÓÃsaveSession()£¬ÇÒûÓÐÌáǰ¹ýÂË \r¡¢\n¡¢= µÈΣÏÕ×Ö·ûµ¼ÖÂsession×ֶα»´«È¾¡£


£¨2£©pass×Ö¶ÎÊÇ·ñ±àÂëÈ¡¾öÓÚ$obÊÇ·ñ´æÔÚ¡£$obÀ´×ԻỰCookieÖжººÅºóµÄƬ¶Î£¬ÀýÈ磺


ͼƬ2.png


ÈôÊÇÒªÇóÖÐֻЯ´ø£º


ͼƬ3.png


Ôò$obΪ¿Õ£¬Cpanel::Session::Encoder²»»á³õʼ»¯£¬pass×Ö¶ÎÒ²²»»á±»±àÂë¡£²¹¶¡ÐÂÔöÁ˶Ôfilter_sessiondata()µÄͳһŲÓ㬲¢ÔÚ$obȱʧʱ½«ÃÜÂë×ֶα£ÁôΪno-ob£º¼ÓÊ®Áù½øÔì±àÂë´ó¾Ö£¬Ô¤·ÀCRLFÔ­Ñù½øÈëraw session¡£


Basic Authenticationõè¾¶´«È¾·ì϶´¥·¢õ辶λÓÚcpsrvd¶ÔBasic AuthenticationµÄ´¦ÖÃÂß¼­¡£ÓйشúÂë¿É³éÏóΪ£º


ͼƬ4.png


ÕâÀïµÄ´àÈõµãÊÇ£º$pass À´×Ô Authorization: Basic ½âÂëºóµÄÃÜÂ벿ÃÅ£¬¶ø set_pass() Ö»ÒƳý NUL ×Ö½Ú£¬²»ÒƳý \r »ò \n¡£Òò¶ø£¬¹¥»÷ÕßÄܹ»ÈàBasic ÈÏÖ¤½âÂëÁ˾ֳöÏÖÈçϽṹ£º


ͼƬ5.png


·þÎñ¶ËÒÀÈ»ÒÔΪx\r\n... ÊÇpass×ֶεÄÖµ£¬µ«µ±Ëü±»Ð´Èëraw sessionÎļþºó£¬Îı¾Îļþ»áÔì³É¶àÐÐkey=value½á¹¹¡£¸Ãõè¾¶»áÖ±½ÓŲÓÃsaveSession()£¬²¢ÇÒ$passÖеÄCRLF»á±»Ð´Èë /var/cpanel/sessions/raw/¡£


·ì϶¸´ÏÖ


£¨1£©WHMÊ×Ò³ÈçÏ£º


ͼƬ6.png


£¨2£©Ö´ÐÐPOC²é¿´ËùÓÐÕ˺ÅÐÅÏ¢


ͼƬ7.png


°²È«½¨Òé


    £¨1£©Á¢¼´Éý¼¶

    cPanel¹Ù·½ÒѰ䲼°²È«²¼¸æ£¬Çë°´Áìµ¼½øÐн¨¸´¡£


    £¨2£©Ò»Ê±»º½â´ëÊ©

    ? ÈôÁÙʱÎÞ·¨Éý¼¶£¬¿ÉÔÚ·À»ðǽÉÏ×èÖ¹¶Ë¿Ú2083¡¢2087¡¢2095ºÍ2096µÄÈëÕ¾Á÷Á¿¡£

    ? »òһʱͣÓÃÓйطþÎñ¡£

    ͼƬ8.png



    ²Î¿¼Á´½Ó£º

    [1]https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026



    ±¦ÔËÀ³¹Ù·½ÍøÕ¾»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


    ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶7000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑÓ×¢µçÐÅÔËÓªÉÌ»ù´¡ÉèÊ©°²È«×êÑÓ×¢ÒÆ¶¯Öն˰²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢5G°²È«×êÑÓ×¢AI°²È«×êÑÓ×¢ÎÀÐǰ²È«×êÑÓ×¢µÍ¿Õ°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£


    adlab.jpg