CVE-2026-41940 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 30, 2026
cPanel and WHM - Authentication Bypass
Overview
cPanel and WHM < 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass caused by a flaw in the login flow, letting unauthenticated remote attackers gain unauthorized access to the control panel, exploit requires no authentication.
Severity & Score
Impact
Unauthenticated remote attackers can gain unauthorized access to the control panel, compromising system security.
Mitigation
Update to version 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 or later.
References
- https://docs.cpanel.net/release-notes/release-notes
- https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- https://docs.wpsquared.com/changelogs/versions/changelog/#13617
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
- https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
- https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
- https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
- https://hadrian.io/blog/cve-2026-41940-a-critical-authentication-bypass-in-cpanel
- https://nvd.nist.gov/vuln/detail/CVE-2026-41940
- https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2026-04-30&host_type=src&vulnerability=cve-2026-41940
- https://www.knownhost.com/forums/threads/cpanel-zero-day-exploit-network-wide-protections-in-place-for-cpanel-and-whm-logins-ports.6599/#post-29956
Social Media Activity(5 posts)
cPanel Flaw Exploited to Deploy Filemanager Backdoor Over 2,000 attacker source IPs worldwide are currently involved in automated attacks exploiting a critical cPanel vulnerability, CVE-2026-41940, which allows remote attackers to gain elevated control and deploy malicious backdoors. This flaw has been targeted by multiple actors for a range of malicious outcomes, including… https://osintsights.com/cpanel-flaw-exploited-to-deploy-filemanager-backdoor?utm_source=mastodon&utm_medium=social #CpanelVulnerability #Cve202641940 #AuthenticationBypass #EmergingThreats #MalwareOperations
View original post📢 CVE-2026-41940 : Zero-day cPanel exploité 64 jours avant divulgation, ransomware et botnet déployés 📝 ## 🗓️ Contexte Article publié le 3 mai 2026 sur webhosting.today pa... 📖 cyberveille : https://cyberveille.ch/posts/2026-05-09-cve-2026-41940-zero-day-cpanel-exploite-64-jours-avant-divulgation-ransomware-et-botnet-deployes/ 🌐 source : https://webhosting.today/2026/05/03/the-cpanel-zero-day-was-active-for-64-days-before-anyone-knew/ #Black_Basta #Brutus_Botnet #Cyberveille
View original postIf you missed this, the updates were released yesterday: https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026 The Hacker News: cPanel, WHM Release Fixes for Three New Vulnerabilities https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html @thehackernews #infosec #vulnerability #cPanel
View original postHackers Exploit CVE-2026-41940 to Take Over cPanel and WHM Servers A critical authentication bypass vulnerability affecting cPanel and WHM servers is currently under active exploitation by a sophis... https://mastodon.social/tags/Cyber https://mastodon.social/tags/Security https://mastodon.social/tags/News https://mastodon.social/tags/Cybersecurity https://mastodon.social/tags/Vulnerability https://mastodon.social/tags/Cyber https://mastodon.social/tags/Security https://mastodon.social/tags/Cyber https://mastodon.social/tags/security https://mastodon.social/tags/news https://mastodon.social/tags/vulnerability https://cyberpress.org/hackers-exploit-cve-2026-41940/ | https://awakari.com/sub-details.html?id=linux | https://awakari.com/pub-msg.html?id=aHrsJo2COKpViVYZKWlp7FzOrVw&interestId=linux
View original postIf you missed this, the updates were released yesterday: https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026 The Hacker News: cPanel, WHM Release Fixes for Three New Vulnerabilities https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html @thehackernews #infosec #vulnerability #cPanel
View original postGitHub Repositories(66 repos)
- https://github.com/YudaSamuel/cpanel-vuln-scanner
- https://github.com/rfxn/cpanel-sessionscribe
- https://github.com/Kagantua/cPanelWHM-AuthBypass
- https://github.com/george1-adel/CVE-2026-41940_exploit
- https://github.com/dennisec/CVE-2026-41940
- https://github.com/debugactiveprocess/cPanel-WHM-AuthBypass-Session-Checker
- https://github.com/44pie/cpsniper
- https://github.com/SreejaPuthan/cpanel-control-plane-exposure-check
- https://github.com/iSee857/cPanel-WHM-CVE-2026-41940-AuthBypass
- https://github.com/ngksiva/cpanel-forensics
- https://github.com/kmaruthisrikar/CVE-2026-41940-cPanel-Auth-Bypass-Exploit
- https://github.com/anach-ai/CVE-2026-41940
- https://github.com/tfawnies/CVE-2026-41940-next
- https://github.com/zedxod/CVE-2026-41940-POC
- https://github.com/Ap0dexMe0/CVE-2026-41940
- https://github.com/ZildanZ/CVE-2026-41940
- https://github.com/0xBlackash/CVE-2026-41940
- https://github.com/sebinxavi/cve-checker-2026
- https://github.com/Jenderal92/CVE-2026-41940
- https://github.com/realawaisakbar/CVE-2026-41940-Exploit-PoC
- https://github.com/senyx122/CVE-2026-41940
- https://github.com/Lutfifakee-Project/CVE-2026-41940
- https://github.com/0xabdoulaye/CPANEL-CVE-2026-41940
- https://github.com/Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC
- https://github.com/habibkaratas/sorry-ransomware-analysis
- https://github.com/assetnote/cpanel2shell-scanner
- https://github.com/Sachinart/CVE-2026-41940-cpanel-0day
- https://github.com/Unfold-Security/CVE-2026-41940-Detection
- https://github.com/0dev1337/cpanelscanner
- https://github.com/adriyansyah-mf/cve-2026-41940-poc
- https://github.com/branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP2
- https://github.com/MrAriaNet/cPanel-Fix
- https://github.com/mahfuzreham/cpanel-cve-2026-41940
- https://github.com/Wesuiliye/CVE-2026-41940
- https://github.com/unteikyou/CVE-2026-41940-AuthBypass-Detector
- https://github.com/rdyprtmx/poc-cve-2026-41940
- https://github.com/Ishanoshada/CVE-2026-41940-Exploit-PoC
- https://github.com/shahidmallaofficial/cpanel-cve-2026-41940-fix
- https://github.com/XsanFlip/poc-cpanel-cve-2026-41940
- https://github.com/OhmGun/whmxploit---CVE-2026-41940
- https://github.com/thekawix/CVE-2026-41940
- https://github.com/murrez/CVE-2026-41940
- https://github.com/tahaXafous/CVE_2026_41940_scan_exploit
- https://github.com/cy3erm/CVE-2026-41940-POC
- https://github.com/nickpaulsec/2026-41940-poc
- https://github.com/Richflexpix/cpanel-pwn
- https://github.com/3tternp/CVE-2026-41940---cPanel-WHM-check
- https://github.com/Andrei-Dr/cpanel-cve-2026-41940-ioc
- https://github.com/ynsmroztas/cPanelSniper
- https://github.com/0xF55/cve-2026-41940-exploit
- https://github.com/MrOplus/CVE-2026-41940
- https://github.com/linko-iheb/cve-2026-41940-scanner
- https://github.com/AmirrezaMarzban/portscan-CVE-2026-41940
- https://github.com/itsismarcos/CVE-2026-41940
- https://github.com/vineet7800/cpanel-malware-cleaner-cve-2026
- https://github.com/bughunt4me/cpanelCVE-2026-41940
- https://github.com/devtint/CVE-2026-41940
- https://github.com/imbas007/POC_CVE-2026-41940
- https://github.com/ilmndwntr/CVE-2026-41940-MASS-EXPLOIT
- https://github.com/NULL200OK/cve-2026-41940-tool
- https://github.com/sercanokur/CVE-2026-41940-cPanel-WHM-Verification-Tool
- https://github.com/Underh0st/CPanel-Audit-Remediation-Tool
- https://github.com/acuciureanu/cpanel2shell-honeypot
- https://github.com/zycoder0day/CVE-2026-41940
- https://github.com/Christian93111/CVE-2026-41940
- https://github.com/merdw/cPanel-CVE-2026-41940-Scanner
Related Resources
Details
- CVE ID
- CVE-2026-41940
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- broken_authentication
- Status
- confirmed
- EPSS
- 6701.4%
- Nuclei
- Available
- Social Posts
- 5
CWE
- CWE-306
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H