SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP cPanel and WHM authentication bypass attempt
This rule looks for the injection of an internal session management value leading to authentication bypass in cPanel and WHM.
This rule blocks attempts to exploit an authentication bypass vulnerability in cPanel and WHM.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::High
Vulnerability::Severity::Critical
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2026-41940 |
Loading description
|