CVE-2026-41940

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*

History

30 Apr 2026, 19:51

Type Values Removed Values Added
First Time Cpanel wp Squared
Cpanel cpanel
Cpanel
Cpanel whm
CPE cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*
References () https://docs.cpanel.net/release-notes/release-notes - () https://docs.cpanel.net/release-notes/release-notes - Release Notes
References () https://docs.wpsquared.com/changelogs/versions/changelog/#13617 - () https://docs.wpsquared.com/changelogs/versions/changelog/#13617 - Release Notes
References () https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 - () https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 - Vendor Advisory
References () https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 - () https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 - Third Party Advisory
References () https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow - () https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow - Third Party Advisory
References () https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py - () https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py - Exploit, Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 - US Government Resource

30 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 16:16

Updated : 2026-04-30 19:51


NVD link : CVE-2026-41940

Mitre link : CVE-2026-41940

CVE.ORG link : CVE-2026-41940


JSON object : View

Products Affected

cpanel

  • whm
  • wp_squared
  • cpanel
CWE
CWE-306

Missing Authentication for Critical Function