Critical SEVERITY — Vulnerability

CVE-2026-41940 — cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthe

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Platform
cPanel & WHM
CVE Record
CVE-2026-41940
CVSS Score
9.3/10
Published
29 April 2026
Views
24
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Assessment

  • CVE: CVE-2026-41940
  • CVSS taban puanı: 9.3
  • Vektör: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Kaynak: NVD kaydı

References

Action

  • Etkilenen sistemleri envanterden doğrulayın
  • Üretici yamasını bakım penceresinde uygulayın
  • Yama uygulanana kadar erişimi ağ katmanında kısıtlayın
cpanel * whm * wp squared *

cPanel & WHM — Related Advisories

VIEW ALL →