Vulnerability threat dossier

CVE-2026-41940

cpanelcpanel

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

VTP deterministic threat61.7of 100 · CVSS excluded

VTP analyst assessment

cPanel authentication bypass with known exploitation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

cPanel, WHM, and WP2 have an unauthenticated login-flow bypass. CISA KEV and ENISA EU KEV list it as known to be exploited. Supplied evidence also shows Nuclei template coverage.

Why it matters

  • An unauthenticated remote attacker could gain control-panel access.
  • CISA marks known ransomware campaign use.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied evidence does not show VTP observation.

The Nuclei release note does not establish exploit reliability.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Review in your environment: if you use cPanel, WHM, or WP2, check affected control-panel exposure.

AI baseline history (3)
  1. BASELINE ASSESSED
    cPanel authentication bypass with known exploitationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    cPanel and WHM authentication bypassgpt-5.6-sol · high
  3. BASELINE ASSESSED
    cPanel and WHM unauthenticated login bypassgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.3 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.99; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-41940ACTIVE
Evidence
04

Event history

Threat timeline

  1. 17:0505 May
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-41940.

  2. 00:0030 Apr
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  3. 00:0030 Apr
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an

CVE-2026-41940CVE-2026-48172CVE-2026-54420CVE-2026-58047CVE-2026-58048CVE-2026-65643
Separate evidence group
Original

Nuclei Templates v10.4.3 - Release Notes

New Templates Added: 105 | CVEs Added: 62 | First-time contributions: 12 🔥 Release Highlights 🔥 [ CVE-2026-42167 ] ProFTPD mod_sql - Preauth User Backdoor ( @pussycat0x ) [high] 🔥 [ CVE-2026-41179 ] RClone RC - Command Injection ( @theamanrawat ) [critical] 🔥 [ CVE-2026-41176 ] Rclone RC - Broken Access Control ( @theamanrawat ) [critical] 🔥 [ CVE-2026-40466 ] Apache ActiveMQ - RCE via HTTP Discovery Transport Bypass ( @dhiyaneshdk ) [high] 🔥 [ CVE-2026-39808 ] Fortinet FortiSandbox - Command Injection ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-39363 ] Vite Dev Server - Arbitrary File Read ( @theamanrawat ) [high] 🔥 [ CVE-2026-35029 ] LiteLLM - Arbitrary File Read ( @theamanrawat ) [high] 🔥 [ CVE-2026-33626 ] LMDeploy - Server-Side Request Forgery ( @theamanrawat ) [high] (kev) (vKEV) 🔥 [ CVE-2026-33439 ] OpenAM <= 16.0.5 - Pre-Auth RCE via jato.clientSession Deserialization ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-33032 ] Nginx UI - Broken Access Control ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-33017 ] Langflow < 1.9.0 - Remote Code Execution ( @himind ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-27174 ] MajorDoMo - Unauthenticated RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-24423 ] SmarterMail - Remote Code Execution ( @jyoti369 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-4631 ] Cockpit Web Console < 360 - Remote Code Execution ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-3844 ] Breeze <= 2.4.4 - Arbitrary File Upload ( @theamanrawat , @ritikchaddha ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-13390 ] WP Directory Kit <= 1.4.4 - Authentication Bypass (@maxthepm) [critical] (kev) (vKEV) 🔥 [ CVE-2021-3152 ] Home Assistant HACS - Local File Inclusion ( @dhiyaneshdk ) [high] 🔥 What's Changed Bug Fixes CI: migrated nuclei GitHub action to native Node.js runtime (PR #16061 , PR #16049 ). Removed duplicate template for BeyondTrust (PR #16024 ). Removed duplicate matcher line in roundcube-log-disclosure.yaml (PR #16042 ). Corrected invalid cve-id classification field values across templates (PR #16023 ). Fixed invalid CPE format strings across templates (PR #15991 , PR #15828 ). Fixed tag formatting in CVE-2024-57727 , CVE-2023-38875 , CVE-2023-24322 (PR #15989 , PR #15897 , PR #15899 ). Corrected YAML formatting in Retool postMessage XSS template (PR #15952 ). Fixed file path for CVE-2026-2262 (PR #15998 ). Renamed joomla-htaccess.yaml → joomla-htaccess-file.yaml for clarity (PR #15987 ). Renamed contrastapi-domain-recon.yaml to correct directory (PR #16025 ). Renamed and updated superset-default-login.yaml (PR #15822 ). Release preparation for Nuclei Templates v10.4.2 (PR #15920 ). False Negatives Fixed FN in tomcat-default-login by ordering payloads to avoid LockOutRealm shunning (PR #16053 , Issue #15382 ). False Positives Reduced false positives and improved accuracy in the following templates: ingress-nginx-valid-admission.yaml — added 200-status guard for verbose-debug PHP frameworks (PR #16046 , Issue #14248 ). CVE-2024-2473 — verify hidden login URL disclosure to avoid FP on WPS Hide Login (PR #15985 , Issue #15871 ). CVE-2019-5544 — fix FP triggered when port 427 is closed (PR #15979 , Issue #15098 ). CVE-2023-45648 — bound Tomcat version regex (PR #15459 , Issue #15566 ). ldap-anonymous-login-detect.yaml — honor Port parameter instead of forcing 389 (PR #15430 , Issue #14736 ). sentry-panel — added title check to prevent FP (PR #15984 ). Enhancements Added Microsoft domain to mx-service-detector (PR #16030 ). Added registrar extractors to rdap-whois template (PR #15908 ). Added references to CVE-2020-15718 (PR #16058 ). Updated mitel-version-detect.yaml (PR #15839 ). Linked CVE-2021-31589 to existing beyond-trust-xss.yaml (Issue #15273 ). Templates Added [ CVE-2026-42167 ] ProFTPD mod_sql - Preauth User Backdoor ( @pussycat0x ) [high] 🔥 [ CVE-2026-42031 ] CKAN DataStore SQL Search - SQL Injection ( @theamanrawat ) [high] [ CVE-2026-41940 ] cPanel & WHM - Auth Bypass via Session-File CRLF Injection ( @wat

CVE-2017-6478CVE-2019-5544CVE-2020-15718CVE-2021-26947CVE-2021-3152CVE-2021-31589CVE-2021-45328CVE-2023-24322CVE-2023-38875CVE-2023-45648CVE-2023-49438CVE-2024-2473CVE-2024-26291CVE-2024-32825CVE-2024-38773CVE-2024-57727CVE-2025-10162CVE-2025-10897CVE-2025-11693CVE-2025-13390CVE-2025-1361CVE-2025-13801CVE-2025-23211CVE-2025-32395CVE-2025-41242CVE-2025-4524CVE-2025-49002CVE-2025-58226CVE-2025-59136CVE-2025-59341CVE-2025-59342CVE-2025-59582CVE-2025-62039CVE-2025-69411CVE-2025-9209CVE-2026-0560CVE-2026-1314CVE-2026-1368CVE-2026-21484CVE-2026-2262CVE-2026-23482CVE-2026-23483CVE-2026-23486CVE-2026-24423CVE-2026-27174CVE-2026-27176CVE-2026-28409CVE-2026-33017CVE-2026-33032CVE-2026-33057CVE-2026-33439CVE-2026-33626CVE-2026-35029CVE-2026-3844CVE-2026-39339CVE-2026-39363CVE-2026-39808CVE-2026-40105CVE-2026-40242CVE-2026-40308CVE-2026-40466CVE-2026-40887CVE-2026-41176CVE-2026-41179CVE-2026-41640CVE-2026-41641CVE-2026-41940CVE-2026-42031CVE-2026-42167CVE-2026-4631
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-41940

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-41940
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.7vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.71 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-306
CPE records
3
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.