Back

CRITICAL KEV Used in ransomware campaigns

WebPros cPanel and WHM Authentication Bypass via Login Flow

Published Apr 29, 2026 ·Due May 3, 2026

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 29, 2026
Updated Sep 30, 2026
Reserved Apr 22, 2026
CISA Vulnrichment
Updated Apr 30, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a