CVE-2026-41940: CWE-306 Missing Authentication for Critical Function in WebPros cPanel
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
AI Analysis
Technical Summary
CVE-2026-41940 is an authentication bypass vulnerability in WebPros cPanel and WHM products starting from version 11.40. This flaw allows unauthenticated remote attackers to bypass the login flow and gain unauthorized access to the control panel. The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function). The CVSS 4.0 vector indicates it is remotely exploitable with no privileges or user interaction required, and it has high impact on confidentiality, integrity, and availability. There is no vendor advisory or patch information currently available, and no known exploits in the wild have been reported.
Potential Impact
Successful exploitation of this vulnerability allows an unauthenticated attacker to bypass authentication controls and gain unauthorized access to the cPanel control panel. This can lead to full compromise of the affected system, including unauthorized administrative actions, data exposure, and potential system disruption. The critical CVSS score of 9.3 reflects the high severity and potential impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the cPanel interface to trusted networks only and monitor for any suspicious access attempts. Avoid exposing the control panel to the public internet if possible.
Indicators of Compromise
- domain: diamond-cli-znsxphqell.cn-shanghai.fcapp.run
- url: https://aone-cli-next.oss-cn-beijing.aliyuncs.com/config/setting.js
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.js
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli-deps.tar.gz
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli
- url: https://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.zip
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/plugins/crypto.js
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit.js
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/app.asar
- url: https://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit-update
- hash: 84a6ccaaab1596139d28e822f40cc99c68d337d4c81d1c6d9692c1d6bb22e4af
- hash: 6044974c633b3a319c31bb32110411520c425e89722a64806528553227e7a50a
- hash: 0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3
- hash: b8b81af76163bdcc5b4f7d8fe6795f164991f8a62678c971db031b9e90a27813
- hash: ef9a1896eeaae929800eade768276e2240ef252d26d0d96c1950a1a5e1aadb34
- hash: e5d8350f1540fe91145dc262c455bca7748ad97dafb2d9facd5adebed9f66d2d
- hash: 41957bd0ba2d9c07af2e069f10780fdf6b2102c065bebe0db2136dfe07d67a28
- hash: 33b58598eb317553942e27545982d4c25ce6120eae10e42393746eb0e02ecae9
- hash: 3201d407b7899a12d6d439950511c6a5
CVE-2026-41940: CWE-306 Missing Authentication for Critical Function in WebPros cPanel
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVSS v4.0
Score 9.3critical
Affected software
WebPros
cPanel
WebPros
WP Squared
WebPros
WHM
pkg:github/webpros/cpanelRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-41940 is an authentication bypass vulnerability in WebPros cPanel and WHM products starting from version 11.40. This flaw allows unauthenticated remote attackers to bypass the login flow and gain unauthorized access to the control panel. The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function). The CVSS 4.0 vector indicates it is remotely exploitable with no privileges or user interaction required, and it has high impact on confidentiality, integrity, and availability. There is no vendor advisory or patch information currently available, and no known exploits in the wild have been reported.
Potential Impact
Successful exploitation of this vulnerability allows an unauthenticated attacker to bypass authentication controls and gain unauthorized access to the cPanel control panel. This can lead to full compromise of the affected system, including unauthorized administrative actions, data exposure, and potential system disruption. The critical CVSS score of 9.3 reflects the high severity and potential impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the cPanel interface to trusted networks only and monitor for any suspicious access attempts. Avoid exposing the control panel to the public internet if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-04-22T18:50:43.621Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindiamond-cli-znsxphqell.cn-shanghai.fcapp.run | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://aone-cli-next.oss-cn-beijing.aliyuncs.com/config/setting.js | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.js | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli-deps.tar.gz | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli | — | |
urlhttps://aone-ai-cli.oss-cn-beijing.aliyuncs.com/app/release/aone-cli.zip | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/plugins/crypto.js | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit.js | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/app.asar | — | |
urlhttps://aone-kit.oss-cn-beijing.aliyuncs.com/aone-kit-update/aone-kit-update | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash84a6ccaaab1596139d28e822f40cc99c68d337d4c81d1c6d9692c1d6bb22e4af | — | |
hash6044974c633b3a319c31bb32110411520c425e89722a64806528553227e7a50a | — | |
hash0910ecfa049738ef3f2540855341a380df89224ff71da94b4c21689fd66f62e3 | — | |
hashb8b81af76163bdcc5b4f7d8fe6795f164991f8a62678c971db031b9e90a27813 | — | |
hashef9a1896eeaae929800eade768276e2240ef252d26d0d96c1950a1a5e1aadb34 | — | |
hashe5d8350f1540fe91145dc262c455bca7748ad97dafb2d9facd5adebed9f66d2d | — | |
hash41957bd0ba2d9c07af2e069f10780fdf6b2102c065bebe0db2136dfe07d67a28 | — | |
hash33b58598eb317553942e27545982d4c25ce6120eae10e42393746eb0e02ecae9 | — | |
hash3201d407b7899a12d6d439950511c6a5 | — |
Threat ID: 69f22c83cbff5d86102980f5
Added to database: 04/29/2026, 16:06:27 UTC
Last enriched: 08/16/2026, 14:44:14 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 524
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.