A severe security flaw has been discovered in cPanel and WHM, two widely used web hosting automation platforms. This vulnerability could allow unauthorized individuals to bypass the login process and gain access to your control panel without needing a password. This is a critical issue that requires immediate attention from system administrators and hosting providers.
Imagine someone gaining full control over your website or server settings without entering any credentials. That’s precisely the risk posed by this authentication bypass. An attacker could potentially compromise your web hosting environment, leading to data breaches, website defacement, or further malicious activities.
CVE Details
Product Name: cPanel, WHM
Published: April 29, 2026
Severity: CRITICAL
Status: Analyzed
Affected Products
This critical authentication bypass vulnerability impacts cPanel and WHM versions released after 11.40. This means that if you are running any version of cPanel or WHM that was released subsequent to version 11.40 and has not yet applied the relevant security patches, your system is at risk. Additionally, cPanel’s WP Squared product, which integrates with WordPress, is also listed among the affected CPEs, indicating potential indirect or related exposure. It is crucial to identify your current version and determine if it falls within the vulnerable range.
Current Status
The vulnerability, identified as CVE-2026-41940, has been officially “Analyzed.” This status confirms that security experts have investigated and confirmed the existence and nature of the flaw. Being analyzed means that the details are understood, and solutions or mitigations are likely available or in the process of being rolled out by the vendor.
Severity Level
This vulnerability carries a “CRITICAL” severity rating, reflected by an extremely high CVSS score of 9.8. A critical rating signifies that the vulnerability is easily exploitable, has a widespread impact, and can lead to severe consequences such as complete system compromise, data loss, or unauthorized access to sensitive information. Given the nature of an authentication bypass, the potential for a full takeover of the control panel is extremely high, making this a top-priority security concern.
Possible Solutions
Given the critical nature of this vulnerability, immediate action is paramount. cPanel has released security updates to address this flaw. We strongly recommend that all cPanel and WHM users update their installations to the latest stable and patched versions as soon as possible. Specifically, a security update was announced on April 28, 2026, which is designed to fix this authentication bypass. Please refer to official cPanel documentation and announcements for the precise patched versions applicable to your installation.
- Regularly check for and apply all available security updates and patches from cPanel.
- Enable two-factor authentication (2FA) for all cPanel and WHM accounts to add an extra layer of security, even if a bypass were to occur.
- Limit access to your cPanel/WHM login pages to trusted IP addresses only, if feasible.
- Monitor your server logs regularly for any suspicious login attempts or unusual activity.
References
https://docs.cpanel.net/release-notes/release-notes
https://docs.wpsquared.com/changelogs/versions/changelog/#13617
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940


