Critical Flaw Exposes cPanel Servers

A critical authentication bypass vulnerability in cPanel & WHM, CVE-2026-41940, allows unauthorized access to millions of domains; patches are available.

Jason Kwon ·

Critical Flaw Exposes cPanel Servers

cPanel/WHM Authentication Bypass Vulnerability Identified A critical authentication bypass vulnerability, identified as CVE-2026-41940, has been discovered in all currently supported versions of cPanel & WHM. This flaw, affecting session loading and saving mechanisms, allows unauthorized access to the administrative interface (WHM) and individual hosting accounts (cPanel) across an estimated 70 million domains globally. Evidence suggests in-the-wild exploitation of this vulnerability as a zero-day has already occurred.

The vulnerability stems from insufficient filtering of session data, specifically the handling of certain characters within session files. Attackers can manipulate session data to bypass authentication, gaining control over server configurations and hosted websites. The flaw was addressed by cPanel through a series of patches released for various versions.

cPanel has released patched versions to mitigate this risk. Users of cPanel & WHM 110.0.x should upgrade to 11.110.0.97, 118.0.x to 11.118.0.63, 126.0.x to 11.126.0.54, 132.0.x to 11.132.0.29, 134.0.x to 11.134.0.20, and 136.0.x to 11.136.0.5. Immediate application of these updates is recommended to prevent potential exploitation.

More stories