← Back to browse · API

CVE-2026-41940

Severity
CRITICAL
CVSS
9.3
EPSS
0.97927
Risk score
59.27
CISA KEV
Yes
PoC
Yes
Published
2026-04-29
Modified
2026-08-04
First seen
2026-08-07
Aliases
EUVD-2026-26246, GHSA-85QR-8RXC-62GV
Products
WebPros:WP Squared patch: 11.136.1.7, WebPros:cPanel & WHM and WP2 (WordPress Squared), WebPros:cPanel 11.104.0.0 <11.110.0.97, WebPros:cPanel 11.112.0.0 <11.118.0.63, WebPros:cPanel 11.120.0.0 <11.124.0.35, WebPros:cPanel 11.126.0.0 <11.126.0.54, WebPros:cPanel 11.128.0.0 <11.130.0.19, WebPros:cPanel 11.132.0.0 <11.132.0.29, WebPros:cPanel 11.134.0.0 <11.134.0.20, WebPros:cPanel 11.136.0.0 <11.136.0.5, WebPros:cPanel 11.40.0.0 <11.86.0.41, WebPros:cPanel 11.88.0.0 <11.94.0.28, WebPros:cPanel 11.96.0.0 <11.102.0.39, cPanel:WHM 11.104.0.0 <11.110.0.97, cPanel:WHM 11.112.0.0 <11.118.0.63, cPanel:WHM 11.120.0.0 <11.124.0.35, cPanel:WHM 11.126.0.0 <11.126.0.54, cPanel:WHM 11.128.0.0 <11.130.0.19, cPanel:WHM 11.132.0.0 <11.132.0.29, cPanel:WHM 11.134.0.0 <11.134.0.20, cPanel:WHM 11.136.0.0 <11.136.0.5, cPanel:WHM 11.40.0.0 <11.86.0.41, cPanel:WHM 11.88.0.0 <11.94.0.28, cPanel:WHM 11.96.0.0 <11.102.0.39
Sources
cisa.gov CVE-2026-41940
euvd EUVD-2026-26246
github e8bc976f744ae06afb15584c|CVE-2026-41940
github 0ceaf58266bc207d4e343893|CVE-2026-41940

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

References