← Back to CVE search

CVE-2026-41940

cPanel and WHM

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVSS 9.8EPSS 97.92699999999999%Risk 9.62
View source
Published
2026-04-29 16:16:25
Affected versions
>11.40
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H