
Detection signatures for CVE-2026-41940 and shemas for cPanel logs
Detection rules and log schemas for the cPanel/WHM authentication bypass (CVE-2026-41940), by Unfold Security.
Blog post: cPanel Exploit — CVE-2026-41940
├── cpanel_cve_2026_41940_mal_get.yml # SIGMA rule — detects the CRLF injection request
├── cpanel_session_mal_authorization.yml # SIGMA rules — detects session use without prior login
├── Schemas/
│ ├── Microsoft Sentinel/ # ARM templates for DCR-based log ingestion into Sentinel
│ └── Splunk/ # props.conf stanzas for cPanel log sourcetypes
├── Sentinel_Detections/ # Microsoft Sentinel analytic rules (KQL queries)
└── Splunk_Detections/ # Splunk Enterprise Security correlation searches