← voltar
CVE-2026-41940

WebPros cPanel and WHM Authentication Bypass via Login Flow

CVSS 9.3 CRITICALEPSS 98.1%● KEVCWE-306
Em resumo

cPanel e WHM possuem uma falha que permite que atacantes acessem a conta sem senha, conseguindo controlar totalmente as contas de hospedagem e servidores.

Detalhe técnico

Um desvio de autenticação no fluxo de login do cPanel/WHM (CWE-306) permite que atacantes remotos não autenticados contornem a validação de credenciais e obtenham acesso não autorizado. A vulnerabilidade afeta versões posteriores à 11.40 e resulta na comprometimento completo do painel de controle.

Resumo gerado e traduzido por IA a partir da descrição oficial.
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
PoCs públicas encontradas28
githubgithub.com/assetnote/cpanel2shell-scanner89githubgithub.com/clsmight/CVE-2026-41940-PoC62githubgithub.com/rfxn/cpanel-sessionscribe13githubgithub.com/bughunt4me/cpanelCVE-2026-4194012githubgithub.com/Christian93111/CVE-2026-419408githubgithub.com/Jenderal92/CVE-2026-419404githubgithub.com/tc4dy/CVE-2026-41940-PoC-Exploit4githubgithub.com/mahfuzreham/cpanel-cve-2026-419403githubgithub.com/44pie/cpsniper2githubgithub.com/murrez/CVE-2026-419401githubgithub.com/MrOplus/CVE-2026-419401githubgithub.com/Unfold-Security/CVE-2026-41940-Detection1githubgithub.com/thekawix/CVE-2026-419401githubgithub.com/sardine-web/Automated-scanner-CVE-2026-419401githubgithub.com/willygailo/CVE-2026-41940-Linux1githubgithub.com/ngksiva/cpanel-forensics0githubgithub.com/anach-ai/CVE-2026-419400githubgithub.com/branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP20githubgithub.com/limo57640-crypto/cpanel-cve-41940-detector0githubgithub.com/xxconi/CVE-2026-419400githubgithub.com/Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC0githubgithub.com/SreejaPuthan/cpanel-control-plane-exposure-check0githubgithub.com/acuciureanu/cpanel2shell-honeypot0githubgithub.com/yurahshell/CVE-2026-419400githubgithub.com/asdasddqwdq29-a11y/CVE-2026-419400githubgithub.com/ZildanZ/CVE-2026-419400cve_referencegithub.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.pynão verificadoexploitdbwww.exploit-db.com/exploits/52574não verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →