critical
CVE-2026-41940
cPanel / WHM authentication bypass - unauthenticated administrative control of the hosting server, all supported versions
- Severity
- critical
- Affected product
- cPanel / WHM
- Affected versions
- cPanel / WHM all versions before the fix
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the cPanel / WHM appliance and reports this CVE when the detected version falls inside the affected range below.
Exploited in the wild before the patch shipped. The cpsrvd banner gives a version, but the fix lands as per-tier builds, so this stays advisory rather than gated.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →