CVE-2026-41940
CRITICAL KEV NUCLEIcPanel and WHM Authentication Bypass via Login Flow
Title source: cnaDescription
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Exploits (23)
github
WORKING POC
2 stars
by adriyansyah-mf · pythonpoc
https://github.com/adriyansyah-mf/cve-2026-41940-poc
github
WORKING POC
1 stars
by NULL200OK · pythonpoc
https://github.com/NULL200OK/cve-2026-41940-tool
github
SCANNER
1 stars
by unteikyou · pythonpoc
https://github.com/unteikyou/CVE-2026-41940-AuthBypass-Detector
github
WORKING POC
1 stars
by george1-adel · pythonpoc
https://github.com/george1-adel/CVE-2026-41940_exploit
github
SCANNER
1 stars
by AndreiG6 · pythonpoc
https://github.com/AndreiG6/cpanel-cve-2026-41940-ioc
github
WRITEUP
1 stars
by Hex0rc1st · pythonpoc
https://github.com/Hex0rc1st/CVE_POC_monitor/tree/main/article/uploads/demo_1777531066/【已复现】cPanel&WHM 身份认证绕过漏洞(CVE-2026-41940)安全风险通告
github
SCANNER
1 stars
by Sachinart · pythonpoc
https://github.com/Sachinart/CVE-2026-41940-cpanel-0day
github
WRITEUP
by shahidmallaofficial · shellpoc
https://github.com/shahidmallaofficial/cpanel-cve-2026-41940-fix
github
WORKING POC
by realawaisakbar · pythonpoc
https://github.com/realawaisakbar/CVE-2026-41940-Exploit-PoC
github
WORKING POC
by debugactiveprocess · pythonpoc
https://github.com/debugactiveprocess/cPanel-WHM-AuthBypass-Session-Checker
Nuclei Templates (1)
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
CRITICALVERIFIEDby watchtowr,hadrian.io,DhiyaneshDk
Shodan:
title:"WHM Login"
References (6)
Scores
CVSS v3
9.8
EPSS
0.1652
EPSS Percentile
94.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
yes
Technical Impact
total
Details
CISA KEV
2026-04-30
VulnCheck KEV
2026-04-28
ENISA EUVD
EUVD-2026-26246
CWE
CWE-306
Status
published
Products (41)
cPanel/cPanel
11.110.0 - 11.110.0.97
cPanel/cPanel
11.118.0 - 11.118.0.63
cPanel/cPanel
11.126.0 - 11.126.0.54
cPanel/cPanel
11.130.0 - 11.130.0.18
cPanel/cPanel
11.132.0 - 11.132.0.29
cPanel/cPanel
11.134.0 - 11.134.0.20
cPanel/cPanel
11.136.0 - 11.136.0.5
cPanel/cPanel
11.86.0 - 11.86.0.41
cPanel/WHM
11.110.0 - 11.110.0.97
cPanel/WHM
11.118.0 - 11.118.0.63
... and 31 more
Published
Apr 29, 2026
KEV Added
Apr 30, 2026
Tracked Since
Apr 29, 2026