CVE-2026-41940 - WHM/cPanel Authentication Bypass Research Tool
Critical WHM/cPanel issue (CVE-2026-41940): pre-authentication bypass chain described in public research, with CVSS ~9.8. Restrict WHM exposure and patch from vendor advisories.
Description
Overview
CVE-2026-41940 is reported as a critical, pre-authentication issue in WHM/cPanel management interfaces. Public write-ups describe an authentication-bypass chain that can yield a privileged WHM session without valid credentials when a host runs a vulnerable build and exposes the service (commonly TCP 2087 for WHM).
Impact
- Confidentiality / integrity / availability: High — administrative control of the hosting panel implies control over sites, accounts, and server configuration.
- Attack vector: Network, pre-auth (as described in third-party research).
- CVSS: Often quoted around 9.8 (Critical) in community summaries; confirm against the authoritative CNA record when available.
Affected scope
Reports reference cPanel & WHM versions after 11.40 as potentially affected. Exact build numbers and fixed versions must be taken from cPanel security advisories and your vendor’s changelog—not from this page alone.
What this PoC entry contains
The downloadable artifact is a research / verification tool referenced in community discussions of CVE-2026-41940. It is intended to help defenders and authorized testers validate patch status and configuration (canonical hostname handling, session behavior, etc.) in lab or explicitly permitted environments.
Legal and ethical use
Use only on systems you own or have written authorization to test. Unauthorized access to WHM/cPanel hosts is illegal in most jurisdictions. pocbit.org publishes PoCs for awareness and defensive validation; operators are responsible for compliance with applicable law and contract terms.
References
- Search CVE-2026-41940 in the CVE Program and NVD for official metadata when published.
- Apply vendor patches and restrict WHM access (firewall, VPN, allowlists) regardless of PoC availability.