CVE-2026-41940

EUVD-2026-26246
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
cpanelcpanel
11.40 ≤
𝑥
< 86.0.41
cpanelcpanel
88.0.0 ≤
𝑥
< 110.0.97
cpanelcpanel
112.0.0 ≤
𝑥
< 118.0.63
cpanelcpanel
120.0.0 ≤
𝑥
< 124.0.35
cpanelcpanel
126.0.1 ≤
𝑥
< 126.0.54
cpanelcpanel
128.0.0 ≤
𝑥
< 130.0.19
cpanelcpanel
132.0.0 ≤
𝑥
< 132.0.29
cpanelcpanel
134.0.0 ≤
𝑥
< 134.0.20
cpanelcpanel
136.0.0 ≤
𝑥
< 136.0.5
cpanelwhm
11.40 ≤
𝑥
< 86.0.41
cpanelwhm
88.0.0 ≤
𝑥
< 110.0.97
cpanelwhm
112.0.0 ≤
𝑥
< 118.0.63
cpanelwhm
120.0.0 ≤
𝑥
< 124.0.35
cpanelwhm
126.0.1 ≤
𝑥
< 126.0.54
cpanelwhm
128.0.0 ≤
𝑥
< 130.0.19
cpanelwhm
132.0.0 ≤
𝑥
< 132.0.29
cpanelwhm
134.0.0 ≤
𝑥
< 134.0.20
cpanelwhm
136.0.0 ≤
𝑥
< 136.0.5
cpanelwp_squared
𝑥
< 136.1.7
𝑥
= Vulnerable software versions
Vulnerability Media Exposure