CVE-2026-41940: WebPros cPanel and WHM Authentication Bypass via Login Flow
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Other sources
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41940?
CVE-2026-41940 is considered a critical vulnerability due to its ability to allow unauthorized access via authentication bypass.
How do I fix CVE-2026-41940?
To fix CVE-2026-41940, upgrade cPanel & WHM to version 11.110.0.98 or later.
Which versions of cPanel & WHM are affected by CVE-2026-41940?
CVE-2026-41940 affects cPanel & WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5.
Can CVE-2026-41940 be exploited remotely?
Yes, CVE-2026-41940 can be exploited by unauthenticated remote attackers.
What components are involved in CVE-2026-41940?
CVE-2026-41940 involves the login flow of cPanel and WHM.