WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Published 26 Aug 2026Updated 26 Aug 2026190 sources
CVSS 9.8 CRITICAL✓ VERIFIED REFERENCE△ CISA KEV

What happened

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Affected versions

cPanel & WHM and WP2 (WordPress Squared): See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52574cPanel - CRLF Injectionnu11secur1ty2026-05-26VerifiedCVE-Intel · Kagantua/cPanelWHM-AuthBypassCVE-2026-41940BypassCRITICALAnalyzed★ 11⑂ 7EPSS 98.53%CVE data: CNAUpdated 26 Aug 2026Kagantua2026-04-30CandidateCVE-Intel · ynsmroztas/cPanelSniperCVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF InjectionInjectionPythonCRITICALAnalyzed★ 494⑂ 137EPSS 98.53%CVE data: CNACode indexedUpdated 25 Aug 2026ynsmroztas2026-05-01CandidateCVE-Intel · lanicer/cve-2026-41940-PoCA cPanel and WHM authentication bypassing toolBypassPythonCRITICALAnalyzed★ 529⑂ 96EPSS 98.53%CVE data: CNACode indexedUpdated 25 Aug 2026Tags: cpanel, cve, cve-2026-41940, cve-scanning, vulnerability-researchlanicer2026-08-19CandidateCVE-Intel · Defacto-ridgepole254/CVE-2026-41940-Exploit-PoCTest authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.BypassCRITICALAnalyzed★ 1⑂ 2EPSS 98.53%CVE data: CNAUpdated 25 Aug 2026Tags: authentication-bypass, cpanel, cpanel-exploit, cve, cve-2026-41940, cve-exploit, exploit, pocDefacto-ridgepole2542026-05-06CandidateCVE-Intel · t4xo/CVE-2026-41940ts zeroday exp made by nullsec white teamZero-DayPythonCRITICALAnalyzed★ 0⑂ 0EPSS 98.53%CVE data: CNACode indexedUpdated 22 Aug 2026t4xo2026-08-22CandidateCVE-Intel · XsanFlip/poc-cpanel-cve-2026-41940PoCPythonCRITICALAnalyzed★ 64⑂ 11EPSS 98.53%CVE data: CNACode indexedUpdated 20 Aug 2026XsanFlip2026-05-01CandidateCVE-Intel · ilmndwntr/CVE-2026-41940-MASS-EXPLOITCVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOITExploitPythonCRITICALAnalyzed★ 14⑂ 9EPSS 98.53%CVE data: CNACode indexedUpdated 19 Aug 2026ilmndwntr2026-04-30CandidateCVE-Intel · murrez/CVE-2026-41940PoC for CVE-2026-41940: WHM/cPanel authentication bypass chain (Python 2.7). For authorized security research and testing only.BypassPythonCRITICALAnalyzed★ 5⑂ 1EPSS 98.53%CVE data: CNACode indexedUpdated 18 Aug 2026murrez2026-05-06Candidatekeithbennedict/CVE-2026-41940-Linux★ 0keithbennedict2026-08-11VerifiedZildanZ/CVE-2026-41940★ 0ZildanZ2026-05-05VerifiedCerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploitCritical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.★ 3CerberusMrXi2026-07-26VerifiedAnotherSec/CVE-2026-41940CVE-2026-41940★ 1AnotherSec2026-07-24Verifiedrazureink/cve-2026-41940-cpanel_authbypass_reproductionCVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction★ 1razureink2026-07-23Verifiedoguz-kagan-akar/CVE-2026-41940-analysisTechnical analysis of the cPanel/WHM auth bypass★ 0oguz-kagan-akar2026-07-18Verifiedtc4dy/CVE-2026-41940-PoC-Exploit🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Advanced PoC for pentesters. ★ 10tc4dy2026-05-12Verifiedgeorge1-adel/CVE-2026-41940_exploit★ 2george1-adel2026-05-01Verified0xgh057r3c0n/CVE-2026-41940cPanel & WHM - Authentication Bypass via Session-File CRLF Injection★ 10xgh057r3c0n2026-09-05Verified