{"id":"CVE-2026-41940","title":"cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.","summary":"cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"cpanel","product":"cpanel","affected":["cpanel >= 11.40, < 86.0.41","cpanel >= 88.0.0, < 110.0.97","cpanel >= 112.0.0, < 118.0.63","cpanel >= 120.0.0, < 124.0.35","cpanel >= 126.0.1, < 126.0.54","cpanel >= 128.0.0, < 130.0.19","cpanel >= 132.0.0, < 132.0.29","cpanel >= 134.0.0, < 134.0.20","cpanel >= 136.0.0, < 136.0.5","whm >= 11.40, < 86.0.41","whm >= 88.0.0, < 110.0.97","whm >= 112.0.0, < 118.0.63","whm >= 120.0.0, < 124.0.35","whm >= 126.0.1, < 126.0.54","whm >= 128.0.0, < 130.0.19","whm >= 132.0.0, < 132.0.29","whm >= 134.0.0, < 134.0.20","whm >= 136.0.0, < 136.0.5","wp_squared < 136.1.7"],"patched":["cpanel 136.0.5","whm 136.0.5","wp_squared 136.1.7"],"published":"2026-04-29","updated":"2026-09-30","sourceUpdated":"2026-09-30T18:18:18.563","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41940","references":[{"url":"https://docs.cpanel.net/release-notes/release-notes","label":"disclosure@vulncheck.com"},{"url":"https://docs.wpsquared.com/changelogs/versions/changelog/#13617","label":"disclosure@vulncheck.com"},{"url":"https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026","label":"disclosure@vulncheck.com"},{"url":"https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow","label":"disclosure@vulncheck.com"},{"url":"https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available","cve.org"],"epss":0.98527,"epssPercentile":0.9992,"kev":true,"kevDateAdded":"2026-04-30","kevDueDate":"2026-05-03","kevRansomware":true,"exploited":true,"exploits":{"exploitdb":true,"github":78,"githubRepos":["https://github.com/ynsmroztas/cPanelSniper","https://github.com/assetnote/cpanel2shell-scanner","https://github.com/XsanFlip/poc-cpanel-cve-2026-41940"],"metasploit":["exploit/multi/http/cpanel_whm_auth_bypass_rce"],"nuclei":["CVE-2026-41940"],"checkedAt":"2026-09-30T19:21:42.186Z"},"exploitAvailable":true,"zeroDay":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-04-29T00:00:00+00:00"},"ingestedAt":"2026-09-30T18:17:24.558Z","slug":"CVE-2026-41940","body":"## Overview\n\ncPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.\n\n## Affected\n\n- `cpanel >= 11.40, < 86.0.41`\n- `cpanel >= 88.0.0, < 110.0.97`\n- `cpanel >= 112.0.0, < 118.0.63`\n- `cpanel >= 120.0.0, < 124.0.35`\n- `cpanel >= 126.0.1, < 126.0.54`\n- `cpanel >= 128.0.0, < 130.0.19`\n- `cpanel >= 132.0.0, < 132.0.29`\n- `cpanel >= 134.0.0, < 134.0.20`\n- `cpanel >= 136.0.0, < 136.0.5`\n- `whm >= 11.40, < 86.0.41`\n- `whm >= 88.0.0, < 110.0.97`\n- `whm >= 112.0.0, < 118.0.63`\n- `whm >= 120.0.0, < 124.0.35`\n- `whm >= 126.0.1, < 126.0.54`\n- `whm >= 128.0.0, < 130.0.19`\n- `whm >= 132.0.0, < 132.0.29`\n- `whm >= 134.0.0, < 134.0.20`\n- `whm >= 136.0.0, < 136.0.5`\n- `wp_squared < 136.1.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `cpanel 136.0.5`\n- `whm 136.0.5`\n- `wp_squared 136.1.7`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":19.7,"exploitation":25,"ransomware":5},"changes":[]}