← Back to CVE List
Vulnerability Intelligence Report
WebPros cPanel and WHM Authentication Bypass via Login Flow

CVE-2026-41940

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:97.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-306 ↗CWE-306 Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
WebPros cPanel 11.40.0.0 < 11.86.0.41 (affected), 11.88.0.0 < 11.94.0.28 (affected), 11.96.0.0 < 11.102.0.39 (affected), 11.104.0.0 < 11.110.0.97 (affected), 11.112.0.0 < 11.118.0.63 (affected), 11.120.0.0 < 11.124.0.35 (affected), 11.126.0.0 < 11.126.0.54 (affected), 11.128.0.0 < 11.130.0.19 (affected), 11.132.0.0 < 11.132.0.29 (affected), 11.134.0.0 < 11.134.0.20 (affected), 11.136.0.0 < 11.136.0.5 (affected)
WebPros WP Squared 11.136.1.7 (unaffected)
WebPros WHM 11.40.0.0 < 11.86.0.41 (affected), 11.88.0.0 < 11.94.0.28 (affected), 11.96.0.0 < 11.102.0.39 (affected), 11.104.0.0 < 11.110.0.97 (affected), 11.112.0.0 < 11.118.0.63 (affected), 11.120.0.0 < 11.124.0.35 (affected), 11.126.0.0 < 11.126.0.54 (affected), 11.128.0.0 < 11.130.0.19 (affected), 11.132.0.0 < 11.132.0.29 (affected), 11.134.0.0 < 11.134.0.20 (affected), 11.136.0.0 < 11.136.0.5 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
97.927%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-04-22T18:50:43
Published2026-04-29T15:10:37
Patch Date2026-04-28
Last Updated2026-08-11T03:55:30

LINK COPIED TO CLIPBOARD