Security advisories

CVE-2026-41940 – cPanel & WHM Authentication Bypass Vulnerability

April 30, 2026

3 MINS READ

The Threat

On April 29th, 2026, cPanel disclosed a critical Authentication Bypass vulnerability, tracked as CVE-2026-41940 (CVSS 9.8), that impacts the control panel solutions cPanel and Web Host Manager (WHM). Exploitation would allow a remote threat actor to bypass authentication requirements and gain access to the control panel.

eSentire is aware of functional Proof-of-Concept (PoC) exploit code, as well as currently unverified claims that the vulnerability was exploited as a zero-day, before patch release. Due to concerns of exploitation, it is critical that impacted organizations apply the relevant cPanel and WHM security patches immediately.

What we're doing about it

What You Should Do About It

Additional Information

cPanel is an extremely popular control panel offering. Estimates state that it is currently used to run more than 70 million domains.

CVE-2026-41940 is an authentication bypass rooted in flawed session loading and saving logic in cPanel and WHM. According to cPanel's advisory, the flaw affects all cPanel software versions after 11.40, including DNSOnly installations. WHM provides root-level administrative access to hosted servers, making unauthorized access via this bypass extremely concerning, as it would enable a variety of malicious actions.

Security researchers from WatchTowr released a technical report and Proof-of-Concept (PoC) exploit code for CVE-2026-41940, simplifying exploit development. The hosting provider KnownHost has claimed that exploitation is already ongoing, although this has not been confirmed by cPanel at the time of writing. The Canadian Centre for Cyber Security (CCCS) has stated that "exploitation is highly probable."

cPanel & WHM
Vulnerable Versions Fixed Versions
prior to 11.110.0.97 11.110.0.97
prior to 11.118.0.63 11.118.0.63
prior to 11.126.0.54 11.126.0.54
prior to 11.130.0.18 11.130.0.18
prior to 11.132.0.29 11.132.0.29
prior to 11.134.0.20 11.134.0.20
prior to 11.136.0.5 11.136.0.5
prior to WP squared 11.136.1.7 WP squared 11.136.1.7

References:
[1] https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-41940
[3] https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
[4] https://www.knownhost.com/forums/threads/cpanel-zero-day-exploit-network-wide-protections-in-place-for-cpanel-and-whm-logins-ports.6599/
[5] https://www.cyber.gc.ca/en/alerts-advisories/al26-008-vulnerability-affecting-cpanel-webhost-manager-whm-cve-2026-41940

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories