CVE-2026-41940

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-04-29 16:16

Updated : 2026-06-17 10:47


NVD link : CVE-2026-41940

Mitre link : CVE-2026-41940

CVE.ORG link : CVE-2026-41940


JSON object : View

Products Affected

cpanel

  • whm
  • wp_squared
  • cpanel
CWE
CWE-306

Missing Authentication for Critical Function