Vulnerability record · CVE-2026-41940 · published 29 April 2026
CVE-2026-41940: cPanel and WHM login flow authentication bypass
Cpanel · Cpanel
cPanel, WHM and WP Squared versions after 11.40 contain a missing-authentication flaw in the login flow (CWE-306) that lets unauthenticated remote attackers reach the control panel without valid credentials. Because the control panel governs hosting accounts, mail, databases and server administration, a bypass there is a direct path to full server compromise.
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated remote authentication bypass with a 9.3 CVSS score, confirmed mass exploitation, KEV listing with known ransomware use, and near-certain EPSS probability.
What it is
cPanel, WHM and WP Squared versions after 11.40 contain a missing-authentication flaw in the login flow (CWE-306) that lets unauthenticated remote attackers reach the control panel without valid credentials. Because the control panel governs hosting accounts, mail, databases and server administration, a bypass there is a direct path to full server compromise.
Impact
An unauthenticated attacker gains unauthorized access to the control panel, and public reporting ties the flaw to post-exploitation leading to remote code execution and ransomware deployment. That access can expose hosted sites, credentials and data on the affected server.
Attack surface
Reached over the network through the login flow itself, with no authentication and no user interaction required, per the CVSS 4.0 vector (AV:N/AC:L/PR:N/UI:N). Any internet-exposed cPanel, WHM or WP Squared login endpoint is in scope.
Exploitation
Exploitation is confirmed: the CVE is in CISA KEV (added 2026-04-30, due 2026-05-03) with known ransomware campaign use, EPSS 30-day probability is 0.98527 (99.9th percentile), and references include public exploit code and press coverage of mass exploitation.
What to do
- Apply the vendor security update for cPanel, WHM and WP Squared per the cPanel security advisory and release notes; this is the only complete fix.
- If patching cannot be done immediately, restrict access to cPanel/WHM login ports (2083, 2087, 2095, 2096) to trusted management IPs or place them behind a VPN.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use of the product where mitigations are unavailable.
- Rotate credentials and API tokens for affected servers and review accounts for unauthorized additions after any exposure window.
- Monitor vendor and CISA advisories for updated guidance, since the KEV due date has already passed.
Detection
- Hunt web and panel logs for successful cPanel/WHM logins that lack a preceding authentication event or come from unexpected source IPs.
- Alert on anomalous access to WHM administrative functions, new account creation, or configuration changes from previously unseen IPs.
- Search for the public watchTowr proof-of-concept request patterns and for post-exploitation activity such as web shells or unexpected processes spawned by panel services.
- Correlate panel access logs with endpoint and network telemetry for signs of ransomware staging on hosting servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-41940 to the Known Exploited Vulnerabilities catalog on 30 April 2026 as "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 May 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-41940 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-41940), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.