CVE-2026-41940
Severity CVSS v4.0:
CRITICAL
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
29/04/2026
Last modified:
04/05/2026
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 11.40 (including) | 86.0.41 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 88.0.0 (including) | 110.0.97 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 112.0.0 (including) | 118.0.63 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 120.0.0 (including) | 124.0.35 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 126.0.1 (including) | 126.0.54 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 128.0.0 (including) | 130.0.19 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 132.0.0 (including) | 132.0.29 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 134.0.0 (including) | 134.0.20 (excluding) |
| cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | 136.0.0 (including) | 136.0.5 (excluding) |
| cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* | 11.40 (including) | 86.0.41 (excluding) |
| cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* | 88.0.0 (including) | 110.0.97 (excluding) |
| cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* | 112.0.0 (including) | 118.0.63 (excluding) |
| cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* | 120.0.0 (including) | 124.0.35 (excluding) |
| cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* | 126.0.1 (including) | 126.0.54 (excluding) |
| cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* | 128.0.0 (including) | 130.0.19 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://docs.cpanel.net/release-notes/release-notes
- https://docs.wpsquared.com/changelogs/versions/changelog/#13617
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
- https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
- https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
- https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
- https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940



