← Back to CVEs
CVE-2026-41940
CRITICALCISA KEV9.8
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/29/2026
Last Modified4/30/2026
Sourcenvd
Honeypot Sightings0
CISA KEV
VendorWebPros
ProductcPanel & WHM and WP2 (WordPress Squared)
Vulnerability NameWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
KEV Date Added2026-04-30
Remediation Due Date2026-05-03
Ransomware UseUnknown
Affected Products
cpanel:cpanelcpanel:whmcpanel:wp_squared
Weaknesses (CWE)
CWE-306
References
https://docs.cpanel.net/release-notes/release-notes(disclosure@vulncheck.com)
https://docs.wpsquared.com/changelogs/versions/changelog/#13617(disclosure@vulncheck.com)
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026(disclosure@vulncheck.com)
https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow(disclosure@vulncheck.com)
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py(134c704f-9b21-4f2e-91b3-4a467353bcc0)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.