cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
CVE-2026-41940
Verified
Description
cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Severity
Critical
Published Date
April 29, 2026
Template Author
watchtowr, hadrian.io, dhiyaneshdk
CVE-2026-41940.yaml
9.5Severity
CVSS Metrics
References
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.pyhttps://hadrian.io/blog/cve-2026-41940-a-critical-authentication-bypass-in-cpanelhttps://nvd.nist.gov/vuln/detail/CVE-2026-41940
Remediation Steps
Update to version 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 or later.