CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Description as published by the source, in English.
Key facts
- Published
- 2026-04-29
- Last modified
- 2026-06-17
- Assigned by
- disclosure@vulncheck.com
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:- Scored by
- disclosure@vulncheck.com
- Probability of exploitation
-
97.9 %
among the highest of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-04-30, with a remediation deadline of 2026-05-03 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Cpanel | Cpanel | ≥ 11.40, < 86.0.41 | Affected |
| Cpanel | Cpanel | ≥ 112.0.0, < 118.0.63 | Affected |
| Cpanel | Cpanel | ≥ 120.0.0, < 124.0.35 | Affected |
| Cpanel | Cpanel | ≥ 126.0.1, < 126.0.54 | Affected |
| Cpanel | Cpanel | ≥ 128.0.0, < 130.0.19 | Affected |
| Cpanel | Cpanel | ≥ 132.0.0, < 132.0.29 | Affected |
| Cpanel | Cpanel | ≥ 134.0.0, < 134.0.20 | Affected |
| Cpanel | Cpanel | ≥ 136.0.0, < 136.0.5 | Affected |
| Cpanel | Cpanel | ≥ 88.0.0, < 110.0.97 | Affected |
| Cpanel | Whm | ≥ 11.40, < 86.0.41 | Affected |
| Cpanel | Whm | ≥ 112.0.0, < 118.0.63 | Affected |
| Cpanel | Whm | ≥ 120.0.0, < 124.0.35 | Affected |
| Cpanel | Whm | ≥ 126.0.1, < 126.0.54 | Affected |
| Cpanel | Whm | ≥ 128.0.0, < 130.0.19 | Affected |
| Cpanel | Whm | ≥ 132.0.0, < 132.0.29 | Affected |
| Cpanel | Whm | ≥ 134.0.0, < 134.0.20 | Affected |
| Cpanel | Whm | ≥ 136.0.0, < 136.0.5 | Affected |
| Cpanel | Whm | ≥ 88.0.0, < 110.0.97 | Affected |
| Cpanel | Wp Squared | < 136.1.7 | Affected |
Weakness type
-
CWE-306: Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References
- https://docs.cpanel.net/release-notes/release-notes
- https://docs.wpsquared.com/changelogs/versions/changelog/#13617
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04…
- https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpane…
- https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
- https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-…
- https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-so…
- https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
Related at Berigo
Articles
-
Critical cPanel flaw exploited at scale in ransomware attacks
Mentions this CVE
2026-05-01
CVE-2026-41940 grants unauthenticated administrator access to cPanel and WHM and is being used to deploy the Sorry ransomware.
-
Permission to park a domain can hand over the entire server
Same product
2026-09-01
cPanel has patched CVE-2026-65643, where a logged-in user with permission to add parked domains can create arbitrary files on the server. Exploitatio…
-
CISA adds two exploited infrastructure vulnerabilities
Same product
2026-06-15
Cisco Catalyst SD-WAN Manager and the LiteSpeed cPanel plugin have entered the KEV catalog after observed exploitation.
-
cPanel fixes three serious vulnerabilities in cPanel and WHM
Same product
2026-05-08
Three cPanel and WHM vulnerabilities can let attackers read files, execute code or escalate privileges on affected systems.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.