CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2026-41940

CVSS 9.3v4.0pub. 2026-04-29upd. 2026-05-04

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

🤖 AI Analysis
How it works

Vulnerability classified as CWE-306 (Missing Authentication for Critical Function) is caused by an error in the login flow that does not require proper authentication for critical panel functions. A remote, unauthenticated attacker can exploit this over the network (AV:N) without any additional conditions (AC:L, AT:N) and without user interaction (UI:N) to bypass authentication mechanisms and gain unauthorized access to the cPanel/WHM panel.

Impact

Attacker gains full unauthorized access to cPanel or WHM control panel, which in practice means the ability to take over managed hosting accounts, modify server configuration, steal data, and install malicious software on hosted websites and the server.

Mitigation & patch

Immediately apply the security update described by the manufacturer in the article 'cPanel & WHM Security Update 04-28-2026' (https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026). Detailed patched version numbers are available in the manufacturer's release notes and WP Squared changelog. Until the patch is implemented, it is recommended to restrict access to cPanel/WHM panel ports (default 2082, 2083, 2086, 2087) exclusively to trusted IP addresses at the firewall level.

Who is affected

cPanel and WHM as well as cPanel WP Squared in versions after 11.40 — detailed list of affected versions indicated in manufacturer's references (docs.cpanel.net and support.cpanel.net).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Cpanel

    APP
    Cpanel
    11.40 – 86.0.41 (excl.)88.0.0 – 110.0.97 (excl.)112.0.0 – 118.0.63 (excl.)120.0.0 – 124.0.35 (excl.)126.0.1 – 126.0.54 (excl.)128.0.0 – 130.0.19 (excl.)132.0.0 – 132.0.29 (excl.)134.0.0 – 134.0.20 (excl.)136.0.0 – 136.0.5 (excl.)
  • Cpanel Whm

    APP
    Cpanel
    11.40 – 86.0.41 (excl.)88.0.0 – 110.0.97 (excl.)112.0.0 – 118.0.63 (excl.)120.0.0 – 124.0.35 (excl.)126.0.1 – 126.0.54 (excl.)128.0.0 – 130.0.19 (excl.)132.0.0 – 132.0.29 (excl.)134.0.0 – 134.0.20 (excl.)136.0.0 – 136.0.5 (excl.)
  • Cpanel Wp Squared

    APP
    Cpanel
    < 136.1.7

CISA KEV — detailsi

Vendori
WebPros
Producti
cPanel & WHM and WP2 (WordPress Squared)
Added to KEVi
April 30, 2026
Remediation deadline (US Federal)i
May 3, 2026(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 3 maja 2026
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-26101CRITICAL9.8PL ✓same product

cPanel: Niezabezpieczone poświadczenia RNDC dla BIND na szablonowych maszynach VM

CVE-2020-26105CRITICAL9.8PL ✓same product

cPanel: Niebezpieczne domyślne dane uwierzytelniające w usłudze chkservd

CVE-2020-26098CRITICAL9.8PL ✓same product

RCE w cPanel – nieprawidłowa obsługa ścieżki filtra Exim

CVE-2020-26100CRITICAL9.8PL ✓same product

Ucieczka z Jailshell przez chsh w cPanel przed wersją 88.0.3

CVE-2020-26108CRITICAL9.8PL ✓same product

cPanel: nieprawidłowa obsługa rozszerzeń plików umożliwia RCE