TROYANOSYVIRUS
Back to CVEs

CVE-2026-41940

CRITICALCISA KEV
9.8

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/29/2026
Last Modified4/30/2026
Sourcenvd
Honeypot Sightings0

CISA KEV

VendorWebPros
ProductcPanel & WHM and WP2 (WordPress Squared)
Vulnerability NameWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
KEV Date Added2026-04-30
Remediation Due Date2026-05-03
Ransomware UseUnknown

Affected Products

cpanel:cpanelcpanel:whmcpanel:wp_squared

Weaknesses (CWE)

CWE-306

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.