cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Vulnerability classified as CWE-306 (Missing Authentication for Critical Function) is caused by an error in the login flow that does not require proper authentication for critical panel functions. A remote, unauthenticated attacker can exploit this over the network (AV:N) without any additional conditions (AC:L, AT:N) and without user interaction (UI:N) to bypass authentication mechanisms and gain unauthorized access to the cPanel/WHM panel.
Attacker gains full unauthorized access to cPanel or WHM control panel, which in practice means the ability to take over managed hosting accounts, modify server configuration, steal data, and install malicious software on hosted websites and the server.
Immediately apply the security update described by the manufacturer in the article 'cPanel & WHM Security Update 04-28-2026' (https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026). Detailed patched version numbers are available in the manufacturer's release notes and WP Squared changelog. Until the patch is implemented, it is recommended to restrict access to cPanel/WHM panel ports (default 2082, 2083, 2086, 2087) exclusively to trusted IP addresses at the firewall level.
cPanel and WHM as well as cPanel WP Squared in versions after 11.40 — detailed list of affected versions indicated in manufacturer's references (docs.cpanel.net and support.cpanel.net).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCpanel
APPCpanel11.40 – 86.0.41 (excl.)88.0.0 – 110.0.97 (excl.)112.0.0 – 118.0.63 (excl.)120.0.0 – 124.0.35 (excl.)126.0.1 – 126.0.54 (excl.)128.0.0 – 130.0.19 (excl.)132.0.0 – 132.0.29 (excl.)134.0.0 – 134.0.20 (excl.)136.0.0 – 136.0.5 (excl.)Cpanel Whm
APPCpanel11.40 – 86.0.41 (excl.)88.0.0 – 110.0.97 (excl.)112.0.0 – 118.0.63 (excl.)120.0.0 – 124.0.35 (excl.)126.0.1 – 126.0.54 (excl.)128.0.0 – 130.0.19 (excl.)132.0.0 – 132.0.29 (excl.)134.0.0 – 134.0.20 (excl.)136.0.0 – 136.0.5 (excl.)Cpanel Wp Squared
APPCpanel< 136.1.7
CISA KEV — detailsi
- Vendori
- WebPros ↗
- Producti
- cPanel & WHM and WP2 (WordPress Squared)
- Added to KEVi
- April 30, 2026
- Remediation deadline (US Federal)i
- May 3, 2026(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Related vulnerabilities
cPanel: Niezabezpieczone poświadczenia RNDC dla BIND na szablonowych maszynach VM
cPanel: Niebezpieczne domyślne dane uwierzytelniające w usłudze chkservd
RCE w cPanel – nieprawidłowa obsługa ścieżki filtra Exim
Ucieczka z Jailshell przez chsh w cPanel przed wersją 88.0.3
cPanel: nieprawidłowa obsługa rozszerzeń plików umożliwia RCE