CVE-2026-41940
About
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Rainforest analyst review
cPanel and WHM builds after 11.40 contain an authentication-bypass flaw in the login flow. A defect in how the login process validates or establishes an authenticated session lets an unauthenticated remote attacker send crafted requests that grant access to the control panel without valid credentials. Once inside WHM or cPanel the attacker holds administrative control over the hosting environment, including account, DNS, and file management.
cPanel and WHM run the management layer for a very large share of shared and reseller web hosting, so a single vulnerable server typically administers many customer websites, databases, and mailboxes. That density makes an auth bypass a multi-tenant event: control of the panel means control over every site it hosts, an attractive target for mass defacement, spam, malware distribution, and credential theft. Apply the cPanel-supplied update immediately, since cPanel's auto-update mechanism is the fastest path to closing this across a fleet, restrict access to the WHM/cPanel management ports where feasible, and audit hosted accounts for unauthorized changes and injected content given how broadly a hosting panel compromise propagates.
References
- https://docs.cpanel.net/release-notes/release-notes
- https://docs.wpsquared.com/changelogs/versions/changelog/#13617
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
- https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
- https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
- https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
- https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
Related CVEs
Frequently asked questions
What is CVE-2026-41940?
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
How severe is CVE-2026-41940?
CVE-2026-41940 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2026-41940 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2026-41940?
Public advisories list the following as affected: cpanel, whm, wp squared. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2026-41940?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
