VDB

CVE-2026-41940

CVE-2026-41940 PUBLISHED KEV CVSS 9.800000190734863 CRITICAL

The vulnerability is caused by improper handling of session data within cPanel & WHM. Due to insufficient sanitisation during session creation and processing, an attacker can craft malicious requests that manipulate how session information is stored and interpreted by the system. By exploiting this flaw, an attacker can inject controlled data into session files and effectively alter authentication-related attributes. This allows the attacker to bypass the normal authentication flow and establish a session that is treated as fully authenticated, even without valid credentials. Once access is obtained, the attacker can operate with administrative privileges. This includes full control over the server, access to hosted websites and databases, and the ability to create persistence mechanisms such as backdoors or additional user accounts. Given the central role of cPanel in hosting environments, this can lead to large-scale compromise affecting multiple customers and services.

EPSS 90.76% · 99.6th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
90.76%
99.6th percentile

Affected Products

VendorProductVersions
cPanelcPanel & WHM (ALL versions)

Timeline

  • CVE Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
  • Apr 29, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›