← Back

CVE-2026-41940

Published: Apr 29, 2026Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Affected (19)

3 products
Cpanel
Whm
Wp Squared
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
From 11.40 to 86.0.41
From 112.0.0 to 118.0.63
From 120.0.0 to 124.0.35
From 126.0.1 to 126.0.54
From 128.0.0 to 130.0.19
From 132.0.0 to 132.0.29
From 134.0.0 to 134.0.20
From 136.0.0 to 136.0.5
From 88.0.0 to 110.0.97
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
From 11.40 to 86.0.41
From 112.0.0 to 118.0.63
From 120.0.0 to 124.0.35
From 126.0.1 to 126.0.54
From 128.0.0 to 130.0.19
From 132.0.0 to 132.0.29
From 134.0.0 to 134.0.20
From 136.0.0 to 136.0.5
From 88.0.0 to 110.0.97
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 136.1.7

Timeline

No history available yet.