Summary
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Assessment
- CVE:
CVE-2026-41940 - CVSS base score: 9.3
- Vector:
CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:N\/SI:N\/SA:N\/E:X\/CR:X\/IR:X\/AR:X\/MAV:X\/MAC:X\/MAT:X\/MPR:X\/MUI:X\/MVC:X\/MVI:X\/MVA:X\/MSC:X\/MSI:X\/MSA:X\/S:X\/AU:X\/R:X\/V:X\/RE:X\/U:X - Source: [NVD record](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-41940)
References
- [docs.cpanel.net](https:\/\/docs.cpanel.net\/release-notes\/release-notes)
- [docs.wpsquared.com](https:\/\/docs.wpsquared.com\/changelogs\/versions\/changelog\/#13617)
- [support.cpanel.net](https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40073787579671-cPanel-WHM-Security-Update-04-28-2026)
- [www.namecheap.com](https:\/\/www.namecheap.com\/status-updates\/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026)
- [www.vulncheck.com](https:\/\/www.vulncheck.com\/advisories\/cpanel-and-whm-authentication-bypass-via-login-flow)
- [labs.watchtowr.com](https:\/\/labs.watchtowr.com\/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940\/)
Actions
- Verify affected systems in inventory
- Apply the vendor patch during a maintenance window
- Restrict access at the network layer until the patch is applied
cpanel *
whm *
wp squared *