Loading market data...
← Back to CVE feed

CVE-2026-41940

CRITICAL CVSS 9.8 View on NVD ↗

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Apr 29, 2026 16:16 UTC Modified: Apr 30, 2026 01:16 UTC