A critical vulnerability in cPanel's Web Host Manager (WHM) has been disclosed, allowing for authentication bypass. This flaw, tracked as CVE-2026-41940, impacts cPanel users who rely on WHM for managing hosting servi…
The vulnerability enables an attacker to bypass authentication mechanisms in WHM. This could lead to unauthorized access to cPanel accounts, potentially allowing attackers to manipulate hosting services, access sensit…
Researchers at WatchTowr Labs discovered and reported the vulnerability. According to their findings, the issue arises from inadequate validation of user input, which can be exploited to circumvent authentication chec…
cPanel has released patches for this vulnerability. Users of WHM are urged to update their installations immediately to prevent exploitation. It is essential for cPanel users to verify their installations are up-to-da…