CVE-2026-41940

Severity CVSS v4.0:
CRITICAL
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
29/04/2026
Last modified:
04/05/2026

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 11.40 (including) 86.0.41 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 88.0.0 (including) 110.0.97 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 112.0.0 (including) 118.0.63 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 120.0.0 (including) 124.0.35 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 126.0.1 (including) 126.0.54 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 128.0.0 (including) 130.0.19 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 132.0.0 (including) 132.0.29 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 134.0.0 (including) 134.0.20 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 136.0.0 (including) 136.0.5 (excluding)
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* 11.40 (including) 86.0.41 (excluding)
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* 88.0.0 (including) 110.0.97 (excluding)
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* 112.0.0 (including) 118.0.63 (excluding)
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* 120.0.0 (including) 124.0.35 (excluding)
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* 126.0.1 (including) 126.0.54 (excluding)
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* 128.0.0 (including) 130.0.19 (excluding)