CVE Watchtower


← Back to CVE List

CVE-2026-41940NVD

Vulnerability Summary

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Severity Level
CRITICAL(9.8)
Published Date
Apr 29, 2026
Last Modified
May 6, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
90.76%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh