cPanel Authentication Bypass

critical Web App Scanning Plugin ID 115231

Synopsis

cPanel Authentication Bypass

Description

cPanel versions greather than 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Solution

Upgrade to cPanel version 11.86.0.41 or 11.110.0.97 or 11.118.0.63 or 11.126.0.54 or 11.130.0.19 or 11.132.0.29 or 11.136.0.5 or 11.134.0.20 or later.

See Also

https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

Plugin Details

Severity: Critical

ID: 115231

Type: Check Based

Published: 5/5/2026

Updated: 5/5/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-41940

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-41940

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-41940

Vulnerability Information

CPE: cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/29/2026

Vulnerability Publication Date: 4/28/2026

CISA Known Exploited Vulnerability Due Dates: 5/3/2026

Reference Information

CVE: CVE-2026-41940