news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-41940

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.8 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk score
100.0
Known exploited
CISA KEVEU KEV
Published
2026-04-29
Status
Analyzed

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Weaknesses

CWE-306

Coverage 3

Advisories and references