Ghostwire

CVE-2026-41940: cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows...

CRITICAL CVSS 9.8 Exploit Available 2 PoC

Published: April 29, 2026 | Last Modified: April 30, 2026

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (2)

Security Coverage (6 articles)

References