CVE-2026-41940
KEV RANSOMWARECRITICAL 9.8EPSS 98.5%
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- CVSS v4.0
- 9.3 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 98.53% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-04-30, used in ransomware campaigns
- Nuclei
- critical
- Published
- 2026-04-29
- Updated
- 2026-08-11
Proof-of-concept exploits (52)
- adriyansyah-mf/cve-2026-41940-poc28★ · 2026-04-30
- XsanFlip/poc-cpanel-cve-2026-4194064★ · 2026-05-01
- Kagantua/cPanelWHM-AuthBypass11★ · 2026-04-30
- realawaisakbar/CVE-2026-41940-Exploit-PoC13★ · 2026-04-30
- bughunt4me/cpanelCVE-2026-4194012★ · 2026-05-09
- Sachinart/CVE-2026-41940-cpanel-0day26★ · 2026-04-29
- 0xYuR1/CVE-2026-4194010★ · 2026-05-16
- senyx122/CVE-2026-419407★ · 2026-05-01
- murrez/CVE-2026-419406★ · 2026-05-12
- AmirrezaMarzban/portscan-CVE-2026-419401★ · 2026-05-01
- Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC1★ · 2026-08-31
- zedxod/CVE-2026-41940-POC2★ · 2026-04-30
- 0xabdoulaye/CPANEL-CVE-2026-419402★ · 2026-04-30
- kmaruthisrikar/CVE-2026-41940-cPanel-Auth-Bypass-Exploit2★ · 2026-05-01
- dennisec/CVE-2026-419400★ · 2026-05-02
- OhmGun/whmxploit---CVE-2026-419400★ · 2026-05-06
- 44pie/cpsniper2★ · 2026-05-10
- 0xBlackash/CVE-2026-419400★ · 2026-05-06
- ZildanZ/CVE-2026-419400★ · 2026-08-09
- Wesuiliye/CVE-2026-419401★ · 2026-04-30
- itsismarcos/CVE-2026-419400★ · 2026-05-04
- devtint/CVE-2026-419400★ · 2026-05-01
- Rosemary1337/CVE-2026-419400★ · 2026-05-01
- MrOplus/CVE-2026-419401★ · 2026-05-08
- anach-ai/CVE-2026-419400★ · 2026-05-13
- tfawnies/CVE-2026-41940-next0★ · 2026-05-03
- rdyprtmx/poc-cve-2026-419400★ · 2026-04-30
- iSee857/cPanel-WHM-CVE-2026-41940-AuthBypass0★ · 2026-05-04
- branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP20★ · 2026-05-08
- Richflexpix/cpanel-pwn0★ · 2026-05-05
- willygailo/CVE-2026-41940-Linux2★ · 2026-05-27
- xxconi/CVE-2026-419400★ · 2026-06-21
- CerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploit3★ · 2026-07-26
- AnotherSec/CVE-2026-419401★ · 2026-07-24
- razureink/cve-2026-41940-cpanel_authbypass_reproduction1★ · 2026-07-23
- lanicer/cve-2026-41940-PoC531★ · 2026-08-20
- t4xo/CVE-2026-419400★ · 2026-08-22
- keithbennedict/CVE-2026-41940-Linux0★ · 2026-08-11
- Ishanoshada/CVE-2026-41940-Exploit-PoC
- Jenderal92/CVE-2026-41940
- NULL200OK/cve-2026-41940-tool
- george1-adel/CVE-2026-41940_exploit
- ilmndwntr/CVE-2026-41940-MASS-EXPLOIT
- imbas007/POC_CVE-2026-41940
- sardine-web/Automated-scanner-CVE-2026-41940
- sercanokur/CVE-2026-41940-cPanel-WHM-Verification-Tool
- tc4dy/CVE-2026-41940-PoC-Exploit
- ynsmroztas/cPanelSniper
- zwanski2019/cPanelSniper
- midox008/cPanelSniper-
- tahaXafous/CVE_2026_41940_scan_exploit
- tc4dy/CVE-2026-6875-PoC-Exploit