CVE-2026-41940

CRITICAL KEV NUCLEI

cPanel and WHM Authentication Bypass via Login Flow

Title source: cna
STIX 2.1

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Exploits (23)

nomisec SCANNER 11 stars
by assetnote · poc
https://github.com/assetnote/cpanel2shell-scanner
nomisec WORKING POC 2 stars
by merdw · poc
https://github.com/merdw/cPanel-CVE-2026-41940-Scanner
github WORKING POC 2 stars
by adriyansyah-mf · pythonpoc
https://github.com/adriyansyah-mf/cve-2026-41940-poc
github WORKING POC 1 stars
by NULL200OK · pythonpoc
https://github.com/NULL200OK/cve-2026-41940-tool
github SCANNER 1 stars
by unteikyou · pythonpoc
https://github.com/unteikyou/CVE-2026-41940-AuthBypass-Detector
github WORKING POC 1 stars
by george1-adel · pythonpoc
https://github.com/george1-adel/CVE-2026-41940_exploit
github SCANNER 1 stars
by AndreiG6 · pythonpoc
https://github.com/AndreiG6/cpanel-cve-2026-41940-ioc
nomisec WRITEUP 1 stars
by rfxn · poc
https://github.com/rfxn/cpanel-sessionscribe
github WRITEUP 1 stars
by Hex0rc1st · pythonpoc
https://github.com/Hex0rc1st/CVE_POC_monitor/tree/main/article/uploads/demo_1777531066/【已复现】cPanel&WHM 身份认证绕过漏洞(CVE-2026-41940)安全风险通告
github SCANNER 1 stars
by Sachinart · pythonpoc
https://github.com/Sachinart/CVE-2026-41940-cpanel-0day
github SUSPICIOUS
by Lutfifakee-Project · poc
https://github.com/Lutfifakee-Project/CVE-2026-41940
github SCANNER
by mahfuzreham · shellpoc
https://github.com/mahfuzreham/cpanel-cve-2026-41940
nomisec WORKING POC
by senyx122 · poc
https://github.com/senyx122/CVE-2026-41940
github WORKING POC
by zedxod · pythonpoc
https://github.com/zedxod/CVE-2026-41940-POC
github WRITEUP
by shahidmallaofficial · shellpoc
https://github.com/shahidmallaofficial/cpanel-cve-2026-41940-fix
github WORKING POC
by 0xabdoulaye · pythonpoc
https://github.com/0xabdoulaye/CPANEL-CVE-2026-41940
nomisec WORKING POC
by ilmndwntr · poc
https://github.com/ilmndwntr/CVE-2026-41940-MASS-EXPLOIT
github WORKING POC
by realawaisakbar · pythonpoc
https://github.com/realawaisakbar/CVE-2026-41940-Exploit-PoC
github WORKING POC
by Wesuiliye · gopoc
https://github.com/Wesuiliye/CVE-2026-41940
nomisec WORKING POC
by Kagantua · poc
https://github.com/Kagantua/cPanelWHM-AuthBypass
github WORKING POC
by debugactiveprocess · pythonpoc
https://github.com/debugactiveprocess/cPanel-WHM-AuthBypass-Session-Checker

Nuclei Templates (1)

cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
CRITICALVERIFIEDby watchtowr,hadrian.io,DhiyaneshDk
Shodan: title:"WHM Login"

Scores

CVSS v3 9.8
EPSS 0.1652
EPSS Percentile 94.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-04-30
VulnCheck KEV 2026-04-28
ENISA EUVD EUVD-2026-26246
CWE
CWE-306
Status published
Products (41)
cPanel/cPanel 11.110.0 - 11.110.0.97
cPanel/cPanel 11.118.0 - 11.118.0.63
cPanel/cPanel 11.126.0 - 11.126.0.54
cPanel/cPanel 11.130.0 - 11.130.0.18
cPanel/cPanel 11.132.0 - 11.132.0.29
cPanel/cPanel 11.134.0 - 11.134.0.20
cPanel/cPanel 11.136.0 - 11.136.0.5
cPanel/cPanel 11.86.0 - 11.86.0.41
cPanel/WHM 11.110.0 - 11.110.0.97
cPanel/WHM 11.118.0 - 11.118.0.63
... and 31 more
Published Apr 29, 2026
KEV Added Apr 30, 2026
Tracked Since Apr 29, 2026