#8
CPanel and WHM Authentication Bypass – CVE-2026-41940
A critical authentication bypass in CPanel and WHM (CVE-2026-41940) earns 92 points and 31 comments, exploiting a timing vulnerability in session token generation that allows remote unauthenticated attackers to gain root access. With a CVSS score of 9.8, this flaw impacts over 1.2 million servers running CPanel 126.0 and earlier, affecting 25% of shared hosting environments.
Photos (1)

Comments on "CPanel and WHM Authentication Bypass – CVE-2026-41940"
Have a take on this ranking?
Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.
No comments yet.
The first comment sets the terms of the argument.