Junglewise Threat Intelligence

CVE-2026-41940: WebPros cPanel & WHM authentication bypass in login flow

CVE-2026-41940 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-04-30

Executive brief

WebPros cPanel & WHM and WP2, which are widely used platforms for managing web hosting and WordPress sites, contain a critical security flaw in their login process. This vulnerability allows an unauthorized person to bypass security checks and gain full administrative control over the hosting panel without needing a password. This could lead to the complete takeover of websites, theft of customer data, or the deployment of ransomware across the server.

Technical details

A missing authentication vulnerability (CWE-306) exists in the login flow of cPanel & WHM and WP2. The flaw allows a remote, unauthenticated attacker to bypass the standard authentication mechanism and gain administrative access to the management interface. This vulnerability is being actively exploited in the wild, including in ransomware campaigns. Attackers can leverage this access to achieve remote code execution (RCE) on the underlying server. Patches have been released by the vendor, and users are urged to update to the latest versions immediately.

Affected products

  • WebPros cPanel & WHM 11.40 through 136.0.4
  • WebPros WP2 (WordPress Squared) Prior to 136.1.7

Timeline

  • 2026-04-28: advisory: Vendor security update released
  • 2026-04-30: disclosed: Public disclosure of CVE-2026-41940
  • 2026-04-30: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-04-30: exploited: Reported as mass-exploited in ransomware attacks

Related threats