CVE-2026-41940 is a critical authentication bypass in WebPros cPanel, WHM, and WP2 (CVSS 9.8) allowing remote attackers to gain full control.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| cpanel | 11.40 | 86.0.41 | vulnerable |
| cpanel | 88.0.0 | 110.0.97 | vulnerable |
| cpanel | 112.0.0 | 118.0.63 | vulnerable |
| cpanel | 120.0.0 | 124.0.35 | vulnerable |
| cpanel | 126.0.1 | 126.0.54 | vulnerable |
| cpanel | 128.0.0 | 130.0.19 | vulnerable |
| cpanel | 132.0.0 | 132.0.29 | vulnerable |
| cpanel | 134.0.0 | 134.0.20 | vulnerable |
| cpanel | 136.0.0 | 136.0.5 | vulnerable |
| whm | 11.40 | 86.0.41 | vulnerable |
| whm | 88.0.0 | 110.0.97 | vulnerable |
| whm | 112.0.0 | 118.0.63 | vulnerable |
| whm | 120.0.0 | 124.0.35 | vulnerable |
| whm | 126.0.1 | 126.0.54 | vulnerable |
| whm | 128.0.0 | 130.0.19 | vulnerable |
| whm | 132.0.0 | 132.0.29 | vulnerable |
| whm | 134.0.0 | 134.0.20 | vulnerable |
| whm | 136.0.0 | 136.0.5 | vulnerable |
| wp_squared | * | 136.1.7 | vulnerable |
Visit the cPanel Security Advisor or the official WebPros support portal to download and apply the emergency security updates released on April 28, 2026, which address the login flow flaw.
Upgrade cPanel & WHM to versions 86.0.41, 110.0.97, 118.0.63, 124.0.35, 126.0.54, 130.0.19, 132.0.29, 134.0.20, 136.0.5 or later, and WP Squared to 136.1.7 or higher to resolve the vulnerability.
Implement network-level access controls or a Web Application Firewall (WAF) to limit access to the cPanel/WHM login ports (2082, 2083, 2086, 2087) to known, trusted IP addresses only.
Review authentication logs for unusual login patterns, specifically looking for successful logins from unknown IP addresses that bypass standard multi-factor authentication or originate from suspicious geographic regions.
Detect exploitation by auditing /usr/local/cpanel/logs/access_log and /var/log/secure for successful login events without corresponding authentication challenges. Look for unusual POST requests to /login/ or /cpsess/ endpoints from external IPs. Network signatures should flag unauthorized traffic to ports 2083 and 2087. Monitor for the creation of unauthorized administrative accounts or unexpected changes to system configuration files immediately following suspicious login activity.
Experience superior visibility and a simpler approach to cyber risk management