CVE-2026-41940: Critical Authentication Bypass Vulnerability in cPanel and WHM
Critical vulnerability (CVSS 9.3) in cPanel and WHM allows administrative access without credentials. Listed in CISA KEV. Update now.
CVE-2026-41940: Critical Authentication Bypass Vulnerability in cPanel and WHM
In short
On April 29, 2026, CVE-2026-41940 [1] was published, a critical vulnerability (CVSS 9.3) [1] in cPanel and WHM that allows any unauthenticated remote attacker to bypass the login process and gain direct access to the server's control panel [1]. The vulnerability is listed in CISA's official Known Exploited Vulnerabilities catalog (KEV) [2], confirming its active exploitation. If your company manages web servers with cPanel or WHM, update immediately and review administrative access.
What it is and why it matters
cPanel and WHM are the most widely used server control panels among web hosting providers and companies that administer their own servers. According to the official description published on NVD, versions of cPanel and WHM later than 11.40 contain a flaw in the login flow that allows an unauthenticated remote attacker to gain unauthorized access to the control panel [1].
> Note on the affected version range: the phrasing "versions later than 11.40" is reproduced here literally as it appears on NVD [1]. This is an unusual phrasing—typically a vulnerability affects installations up to a certain version—so if you have doubts about whether your specific installation falls within the affected range, check directly with cPanel/WHM or your hosting provider.
The severity of this flaw is at its maximum from a business standpoint: no password or credential is needed to exploit it. A successful attacker gains full administrative access, allowing them to modify websites, exfiltrate data, install malicious code, or compromise the end clients hosted on that server [1]. The fact that CISA has added it to its KEV list [2] indicates it is already being actively used in real-world attacks.
The OCIRIA intelligence Radar reinforces this assessment: the flaw particularly affects hosting providers and owners of dedicated or VPS servers, since credential-free access to the control panel is equivalent to holding the keys to the entire building.
Who is affected
- Web hosting providers that offer cPanel/WHM to their customers.
- Companies and freelancers who manage their own server using cPanel or WHM as an administration tool.
- Digital agencies that administer servers on behalf of their clients.
If you don't know which control panel the server hosting your website or application uses, ask your provider or technical lead. This is not a minor detail in this case.
How to know if you are vulnerable
The first step is to confirm whether any of your servers run cPanel or WHM in versions later than 11.40, according to the range indicated by NVD [1]. You can check this by accessing your server's administration panel or requesting the information from your hosting provider.
It is also advisable to review your exposed attack surface: is the WHM access port (typically 2087) accessible from the internet without IP restrictions? The greater the exposure, the greater the risk of already having been compromised.
How to protect yourself
1. Update cPanel and WHM immediately. Apply the patch or update available from the vendor. This is the most urgent action [1].
2. Change all administrative passwords for cPanel, WHM, and hosting accounts, especially if the server has been exposed unpatched.
3. Review the panel's access logs for unauthorized access or unrecognized changes made before the patch was applied.
4. Restrict access to the WHM port using firewalls or IP whitelists, so that only your team's known addresses can access it.
5. Notify your hosting provider if you do not manage the server directly, and request confirmation that they have applied the patch.
Frequently asked questions
Is my website at risk if I use shared hosting with cPanel?
It depends on whether your provider has updated their servers. Ask them directly and request written confirmation.
Can I tell if I've already been attacked?
Review the server's access logs and the control panel for logins at unusual times or changes you don't recognize. If in doubt, contact an incident response specialist.
Does it also affect other products from the same vendor?
The official NVD description mentions exclusively cPanel and WHM [1]. The OCIRIA Radar has gathered indications of possible impact on other products in the WebPros ecosystem, but this point has not been confirmed by NVD or CISA as of the publication date of this post.
What is the CISA KEV list and why is it relevant?
It is the official U.S. Government catalog that lists vulnerabilities with confirmed active exploitation [2]. Its inclusion on this list means the flaw is not theoretical: attackers are using it right now.
Sources
- [1] NVD — Official CVE-2026-41940 record: nvd.nist.gov/vuln/detail/CVE-2026-41940
- [2] CISA — Known Exploited Vulnerabilities catalog (KEV): cisa.gov/known-exploited-vulnerabilities-catalog