cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
04 May 2026, 18:09
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ - Exploit, Third Party Advisory | |
| References | () https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/ - Press/Media Coverage |
04 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Apr 2026, 19:51
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Cpanel wp Squared
Cpanel cpanel Cpanel Cpanel whm |
|
| CPE | cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:* |
|
| References | () https://docs.cpanel.net/release-notes/release-notes - Release Notes | |
| References | () https://docs.wpsquared.com/changelogs/versions/changelog/#13617 - Release Notes | |
| References | () https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 - Vendor Advisory | |
| References | () https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 - Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow - Third Party Advisory | |
| References | () https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py - Exploit, Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 - US Government Resource |
30 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-29 16:16
Updated : 2026-05-04 18:09
NVD link : CVE-2026-41940
Mitre link : CVE-2026-41940
CVE.ORG link : CVE-2026-41940
JSON object : View
Products Affected
cpanel
- cpanel
- whm
- wp_squared
CWE
CWE-306
Missing Authentication for Critical Function
