Live data from Hacker News

CPanel and WHM Authentication Bypass – CVE-2026-41940

labs.watchtowr.com

31–40 of 64 posts

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#31
post #22

Y'know what would help protect those internet buildings from falling on people? A software building code

Really not looking forward to a regulated software industry. It will cause a lot of gatekeeping and bureaucracy. It's one of those things that may seem good, but in practice, it's pure waste in every way imaginable. Will just lead to exclusivity, gatekeeping and artificial friction. This is a hill I'm willing to die on. Those making software have plenty of incentives to make it good, and bad software is punished alre…

Yeah, I hate all those terrible regulations that keep people from burning alive in their homes too. Godddamn goverment saving lives, it's so slightly annoying.

Wait. Wasn't there a whole group of people who thought this way recently? Wasn't it called the Department of Government Efficiency? Wasn't it led by a rich tech bro who wants to live on Mars? Didn't they get disbanded because it was a bunch of armchair experts who knew nothing about government and couldn't make anything efficient?

Maybe you want to apply to whatever they're working on next?

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#32

This flurry of activity is certainly going to have people be more apprehensive about unproven software that may be of dubious prominence. My question amid all of this is who else knew about these long-standing vulnerabilities?

cPanel is just about as far away from “unproven” as possible.

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#33
post #18

Earlier quoted context omitted.

At the rate we are going, we will all go back to publish HTML website like in Geocities times.

Conceptually, static sites are probably not too far off this.

Static sites are just superior and i feel like we are going to see a huge shift to SSGs once the average editors realize how much easier it is to have LLMs enter markdown maybe with a bit of html to create their blog posts/articles than to bother with a CMS.

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#34
post #23

What a shame that I no longer have access to my teenage-level conscience, I am sallivating at the idea of going wild with this and the Copy Fail cve. The potential here to do all kinds of manipulation for search engines / AI tools is enormous. Perhaps the more scary thought is that someone could easily make an agent that would exploit both bugs to wipe out servers. Good on these companies to publish their findings st…

> Good on these companies to publish their findings straight away as I'd imagine that both bugs would have fetched quite a lot on the black market.

You should read the other thread regarding copy fail and the gentoo maintainer. I haven't seen so many unhinged and outright rude comments on a security topic since the good old days of slashdot and x vs. y controversy of the day.

I wonder what the reason behind so much hostility is. Is it gentoo or the kernel folks or the fact that the company that found it used "AI"? No idea, but it was a weird read.

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#35
post #5

Everytime I read one of these it always boils down to the same thing..Don't solve solved problems. And the best code in this case is code you didn't write as PHP's session handler is battle-tested but every line you write to roll your own is a line you have to secure, maintain, and eventually patch at 2am when someone finds the bug. Session handling, auth, crypto, password hashing etc - all these are the exact areas…

But it's not the same thing every time, for example if you had written 'your own' http request you wouldn't habe been hit by the axios vuln.

If you rolled your own crypto and didn't install AF_ALG, you would have avoided copy fail.

Even in this case if you had implemented your own control panel, you wouldn't be hit.

Actually roll your own, don't add dependencies

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#36
post #5

Everytime I read one of these it always boils down to the same thing..Don't solve solved problems. And the best code in this case is code you didn't write as PHP's session handler is battle-tested but every line you write to roll your own is a line you have to secure, maintain, and eventually patch at 2am when someone finds the bug. Session handling, auth, crypto, password hashing etc - all these are the exact areas…

I doubt the mantra of "don't roll your own Auth/crypto" - especially if it lives on a server where the code can't be inspected. Sure, there will be more bugs in my code, but the attackers will be putting far more scrutiny into a widely used library. Some deliberately hilariously weak auth I built decades ago is only just now starting to get broken into by AI bots, whereas any vulnerable wordpress was broken into with…

Thinking of use cases where services I build have reasonably low internal userbase. Maybe rolling out own is not worst choice always. After all it leads to manual or at least targeted work by attackers. Instead of very common spraying stuff randomly. So risks might in the end be lower.

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#37
post #23

What a shame that I no longer have access to my teenage-level conscience, I am sallivating at the idea of going wild with this and the Copy Fail cve. The potential here to do all kinds of manipulation for search engines / AI tools is enormous. Perhaps the more scary thought is that someone could easily make an agent that would exploit both bugs to wipe out servers. Good on these companies to publish their findings st…

> Good on these companies to publish their findings straight away as I'd imagine that both bugs would have fetched quite a lot on the black market. You should read the other thread regarding copy fail and the gentoo maintainer. I haven't seen so many unhinged and outright rude comments on a security topic since the good old days of slashdot and x vs. y controversy of the day. I wonder what the reason behind so much h…

Especially weird when from their description they actually had an idea. ".splice()" and then just searched possibilities of that and then identified place and only then used AI to build something. Which they likely could have done manually too...

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#38
post #23

What a shame that I no longer have access to my teenage-level conscience, I am sallivating at the idea of going wild with this and the Copy Fail cve. The potential here to do all kinds of manipulation for search engines / AI tools is enormous. Perhaps the more scary thought is that someone could easily make an agent that would exploit both bugs to wipe out servers. Good on these companies to publish their findings st…

> Good on these companies to publish their findings straight away as I'd imagine that both bugs would have fetched quite a lot on the black market. You should read the other thread regarding copy fail and the gentoo maintainer. I haven't seen so many unhinged and outright rude comments on a security topic since the good old days of slashdot and x vs. y controversy of the day. I wonder what the reason behind so much h…

> You should read the other thread regarding copy fail and the gentoo maintainer Do you have a link?

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#39
post #38

Earlier quoted context omitted.

> Good on these companies to publish their findings straight away as I'd imagine that both bugs would have fetched quite a lot on the black market. You should read the other thread regarding copy fail and the gentoo maintainer. I haven't seen so many unhinged and outright rude comments on a security topic since the good old days of slashdot and x vs. y controversy of the day. I wonder what the reason behind so much h…

> You should read the other thread regarding copy fail and the gentoo maintainer Do you have a link?

It's this one: https://news.ycombinator.com/item?id=47965108

Re: CPanel and WHM Authentication Bypass – CVE-2026-41940

#40
post #22

Earlier quoted context omitted.

Really not looking forward to a regulated software industry. It will cause a lot of gatekeeping and bureaucracy. It's one of those things that may seem good, but in practice, it's pure waste in every way imaginable. Will just lead to exclusivity, gatekeeping and artificial friction. This is a hill I'm willing to die on. Those making software have plenty of incentives to make it good, and bad software is punished alre…

Yeah, I hate all those terrible regulations that keep people from burning alive in their homes too. Godddamn goverment saving lives, it's so slightly annoying. Wait. Wasn't there a whole group of people who thought this way recently? Wasn't it called the Department of Government Efficiency? Wasn't it led by a rich tech bro who wants to live on Mars? Didn't they get disbanded because it was a bunch of armchair experts…

What regulations would you suggest would be the software equivalent of a fire code?

What kind of penalties would apply for not meeting these regulations?

Who would be responsible for enforcement? Do you propose this should apply internationally? Or just to software written in a specific region? Or is the location of where software is hosted (or the headquarters of the company operating the hardware) a better target for legislation?

Post reply on HN