cPanel and WHM Authentication Bypass Vulnerability (CVE-2026-41940) — Critical Severity

A severe security flaw has been discovered in cPanel and WHM, two widely used web hosting automation platforms. This vulnerability could allow unauthorized individuals to bypass the login process and gain access to your control panel without needing a password. This is a critical issue that requires immediate attention from system administrators and hosting providers.

Imagine someone gaining full control over your website or server settings without entering any credentials. That’s precisely the risk posed by this authentication bypass. An attacker could potentially compromise your web hosting environment, leading to data breaches, website defacement, or further malicious activities.

CVE Details

Product Name: cPanel, WHM
Published: April 29, 2026
Severity: CRITICAL
Status: Analyzed

Affected Products

This critical authentication bypass vulnerability impacts cPanel and WHM versions released after 11.40. This means that if you are running any version of cPanel or WHM that was released subsequent to version 11.40 and has not yet applied the relevant security patches, your system is at risk. Additionally, cPanel’s WP Squared product, which integrates with WordPress, is also listed among the affected CPEs, indicating potential indirect or related exposure. It is crucial to identify your current version and determine if it falls within the vulnerable range.

Current Status

The vulnerability, identified as CVE-2026-41940, has been officially “Analyzed.” This status confirms that security experts have investigated and confirmed the existence and nature of the flaw. Being analyzed means that the details are understood, and solutions or mitigations are likely available or in the process of being rolled out by the vendor.

Severity Level

This vulnerability carries a “CRITICAL” severity rating, reflected by an extremely high CVSS score of 9.8. A critical rating signifies that the vulnerability is easily exploitable, has a widespread impact, and can lead to severe consequences such as complete system compromise, data loss, or unauthorized access to sensitive information. Given the nature of an authentication bypass, the potential for a full takeover of the control panel is extremely high, making this a top-priority security concern.

Possible Solutions

Given the critical nature of this vulnerability, immediate action is paramount. cPanel has released security updates to address this flaw. We strongly recommend that all cPanel and WHM users update their installations to the latest stable and patched versions as soon as possible. Specifically, a security update was announced on April 28, 2026, which is designed to fix this authentication bypass. Please refer to official cPanel documentation and announcements for the precise patched versions applicable to your installation.

  • Regularly check for and apply all available security updates and patches from cPanel.
  • Enable two-factor authentication (2FA) for all cPanel and WHM accounts to add an extra layer of security, even if a bypass were to occur.
  • Limit access to your cPanel/WHM login pages to trusted IP addresses only, if feasible.
  • Monitor your server logs regularly for any suspicious login attempts or unusual activity.

References

https://docs.cpanel.net/release-notes/release-notes

https://docs.wpsquared.com/changelogs/versions/changelog/#13617

https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026

https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026

https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow

https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.