CVE-2026-41940: CWE-306 Missing Authentication for Critical Function in WebPros cPanel
Unknown threat actors distributed malicious downloader functionality across multiple npm packages targeting users of Alibaba tools. The campaign used typosquatting tactics by creating unscoped packages impersonating private packages from Alibaba's @ali scope. Malicious functionality was split across a dependency chain including packages like lib-mtop, smart-config-manager, cloud-config-fetcher, and local-config-parser. The attack employed VM sandbox escape techniques and delivered a sophisticated cross-platform RAT capable of data exfiltration, command execution, and lateral movement through DingTalk collaboration tools. The campaign remained undetected for three months, suggesting possible account takeovers and coordinated publishing across multiple npm accounts in late April 2026, specifically targeting Chinese-speaking developers within Alibaba Group companies for industrial espionage purposes.
AI Analysis
Technical Summary
CVE-2026-41940 is a critical vulnerability classified as CWE-306 (Missing Authentication for Critical Function) affecting WebPros cPanel and WHM versions starting from 11.40. This flaw permits unauthenticated remote attackers to bypass authentication controls and gain unauthorized access to the control panel. The CVSS 4.0 base score is 9.3, reflecting a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability. Currently, there is no official patch or remediation guidance from the vendor, and no exploits have been observed in the wild.
Potential Impact
Successful exploitation of this vulnerability allows unauthenticated remote attackers to gain unauthorized access to the cPanel control panel, potentially compromising confidentiality, integrity, and availability of the affected system. This could lead to full control over hosting environments managed via cPanel.
Mitigation Recommendations
No official patch or remediation guidance is currently available from the vendor. Organizations should monitor vendor advisories for updates. Until a fix is released, consider restricting network access to the cPanel interface to trusted IP addresses and employ additional network-level protections to reduce exposure.
Indicators of Compromise
- domain: diamond-cli-znsxphqell.cn-shanghai.fcapp.run
- url: https://aone-cli-next.oss-cn-beijing.aliyuncs.com/config/setting.js
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.js
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli-deps.tar.gz
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.zip
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/plugins/crypto.js
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit.js
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/app.asar
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit-update
- hash: 84a6ccaaab1596139d28e822f40cc99c68d337d4c81d1c6d9692c1d6bb22e4af
- hash: 6044974c633b3a319c31bb32110411520c425e89722a64806528553227e7a50a
- hash: 0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3
- hash: b8b81af76163bdcc5b4f7d8fe6795f164991f8a62678c971db031b9e90a27813
- hash: ef9a1896eeaae929800eade768276e2240ef252d26d0d96c1950a1a5e1aadb34
- hash: e5d8350f1540fe91145dc262c455bca7748ad97dafb2d9facd5adebed9f66d2d
- hash: 41957bd0ba2d9c07af2e069f10780fdf6b2102c065bebe0db2136dfe07d67a28
- hash: 33b58598eb317553942e27545982d4c25ce6120eae10e42393746eb0e02ecae9
- hash: 3201d407b7899a12d6d439950511c6a5
CVE-2026-41940: CWE-306 Missing Authentication for Critical Function in WebPros cPanel
Description
Unknown threat actors distributed malicious downloader functionality across multiple npm packages targeting users of Alibaba tools. The campaign used typosquatting tactics by creating unscoped packages impersonating private packages from Alibaba's @ali scope. Malicious functionality was split across a dependency chain including packages like lib-mtop, smart-config-manager, cloud-config-fetcher, and local-config-parser. The attack employed VM sandbox escape techniques and delivered a sophisticated cross-platform RAT capable of data exfiltration, command execution, and lateral movement through DingTalk collaboration tools. The campaign remained undetected for three months, suggesting possible account takeovers and coordinated publishing across multiple npm accounts in late April 2026, specifically targeting Chinese-speaking developers within Alibaba Group companies for industrial espionage purposes.
CVSS v4.0
Score 9.3critical
Affected software
pkg:github/webpros/cpanelRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-41940 is a critical vulnerability classified as CWE-306 (Missing Authentication for Critical Function) affecting WebPros cPanel and WHM versions starting from 11.40. This flaw permits unauthenticated remote attackers to bypass authentication controls and gain unauthorized access to the control panel. The CVSS 4.0 base score is 9.3, reflecting a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability. Currently, there is no official patch or remediation guidance from the vendor, and no exploits have been observed in the wild.
Potential Impact
Successful exploitation of this vulnerability allows unauthenticated remote attackers to gain unauthorized access to the cPanel control panel, potentially compromising confidentiality, integrity, and availability of the affected system. This could lead to full control over hosting environments managed via cPanel.
Mitigation Recommendations
No official patch or remediation guidance is currently available from the vendor. Organizations should monitor vendor advisories for updates. Until a fix is released, consider restricting network access to the cPanel interface to trusted IP addresses and employ additional network-level protections to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-04-22T18:50:43.621Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindiamond-cli-znsxphqell.cn-shanghai.fcapp.run | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://aone-cli-next.oss-cn-beijing.aliyuncs.com/config/setting.js | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.js | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli-deps.tar.gz | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.zip | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/plugins/crypto.js | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit.js | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/app.asar | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit-update | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash84a6ccaaab1596139d28e822f40cc99c68d337d4c81d1c6d9692c1d6bb22e4af | — | |
hash6044974c633b3a319c31bb32110411520c425e89722a64806528553227e7a50a | — | |
hash0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3 | — | |
hashb8b81af76163bdcc5b4f7d8fe6795f164991f8a62678c971db031b9e90a27813 | — | |
hashef9a1896eeaae929800eade768276e2240ef252d26d0d96c1950a1a5e1aadb34 | — | |
hashe5d8350f1540fe91145dc262c455bca7748ad97dafb2d9facd5adebed9f66d2d | — | |
hash41957bd0ba2d9c07af2e069f10780fdf6b2102c065bebe0db2136dfe07d67a28 | — | |
hash33b58598eb317553942e27545982d4c25ce6120eae10e42393746eb0e02ecae9 | — | |
hash3201d407b7899a12d6d439950511c6a5 | — |
Threat ID: 69f22c83cbff5d86102980f5
Added to database: 04/29/2026, 16:06:27 UTC
Last enriched: 07/24/2026, 20:52:24 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 486
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.