CVE-2026-41940
WebPros cPanel and WHM Authentication Bypass via Login Flow
- Published
- Apr 29, 2026
- Updated
- Aug 11, 2026
- Assigning CNA
- VulnCheck
- Evidence observed
- Apr 30, 2026
Primary CVSS
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Sources
65- CVE-2026-41940Exploit
CVE-2026-41940
- CVE-2026-41940Exploit
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
- CVE-2026-41940Exploit
cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.