CVE-2026-41940
WebPros cPanel and WHM Authentication Bypass via Login Flow
Em resumo
cPanel e WHM possuem uma falha que permite que atacantes acessem a conta sem senha, conseguindo controlar totalmente as contas de hospedagem e servidores.
Detalhe técnico
Um desvio de autenticação no fluxo de login do cPanel/WHM (CWE-306) permite que atacantes remotos não autenticados contornem a validação de credenciais e obtenham acesso não autorizado. A vulnerabilidade afeta versões posteriores à 11.40 e resulta na comprometimento completo do painel de controle.
Resumo gerado e traduzido por IA a partir da descrição oficial.
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
PoCs públicas encontradas — 28
githubgithub.com/assetnote/cpanel2shell-scanner★ 89githubgithub.com/clsmight/CVE-2026-41940-PoC★ 62githubgithub.com/rfxn/cpanel-sessionscribe★ 13githubgithub.com/bughunt4me/cpanelCVE-2026-41940★ 12githubgithub.com/Christian93111/CVE-2026-41940★ 8githubgithub.com/Jenderal92/CVE-2026-41940★ 4githubgithub.com/tc4dy/CVE-2026-41940-PoC-Exploit★ 4githubgithub.com/mahfuzreham/cpanel-cve-2026-41940★ 3githubgithub.com/44pie/cpsniper★ 2githubgithub.com/murrez/CVE-2026-41940★ 1githubgithub.com/MrOplus/CVE-2026-41940★ 1githubgithub.com/Unfold-Security/CVE-2026-41940-Detection★ 1githubgithub.com/thekawix/CVE-2026-41940★ 1githubgithub.com/sardine-web/Automated-scanner-CVE-2026-41940★ 1githubgithub.com/willygailo/CVE-2026-41940-Linux★ 1githubgithub.com/ngksiva/cpanel-forensics★ 0githubgithub.com/anach-ai/CVE-2026-41940★ 0githubgithub.com/branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP2★ 0githubgithub.com/limo57640-crypto/cpanel-cve-41940-detector★ 0githubgithub.com/xxconi/CVE-2026-41940★ 0githubgithub.com/Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC★ 0githubgithub.com/SreejaPuthan/cpanel-control-plane-exposure-check★ 0githubgithub.com/acuciureanu/cpanel2shell-honeypot★ 0githubgithub.com/yurahshell/CVE-2026-41940★ 0githubgithub.com/asdasddqwdq29-a11y/CVE-2026-41940★ 0githubgithub.com/ZildanZ/CVE-2026-41940★ 0cve_referencegithub.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.pynão verificadoexploitdbwww.exploit-db.com/exploits/52574não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://docs.cpanel.net/release-notes/release-noteshttps://docs.wpsquared.com/changelogs/versions/changelog/#13617https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.pyhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow