CRITICAL

CVE-2026-41940

Cpanel Wp Squared 2026-04-29 CVSS v3.1
CVSS
9.8
KEV

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Summary dbcve.org

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized administrative access to the control panel. The flaw appears to be in the authentication mechanism itself, enabling attackers to circumvent login verification entirely.

Mitigation

Update cPanel/WHM to the latest version containing the security patch. As an interim measure, restrict network access to the cPanel/WHM interfaces using firewall rules or IP allow-listing until the patch can be applied.

Proof of Concept

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

98.53%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE