PoC Index

CVE-2026-41940

KEV RANSOMWARECRITICAL 9.8EPSS 98.5%

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVSS v4.0
9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
98.53% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2026-04-30, used in ransomware campaigns
Nuclei
critical
Published
2026-04-29
Updated
2026-08-11

Proof-of-concept exploits (52)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related