cPanel WHM Authentication Bypass Admin Access | MSSP Advisory

Critical
DateMay 1, 2026
📋Executive Summary
A critical authentication bypass vulnerability exists in cPanel & WHM (CVE-2026-41940) that allows attackers to gain administrative access without valid credentials. The flaw affects the core authentication mechanism in these widely deployed web hosting management platforms. Successful exploitation grants complete control over web hosting environments and all hosted sites.
⚠️Why It Matters for MSSPs
Your RMM endpoints accessing client hosting environments could be compromised if those clients run cPanel installations, creating a backdoor into your management infrastructure. Every hosting client you manage becomes a liability until patched, and if their sites get compromised through this bypass while you knew about it, you own that conversation with them and potentially their customers.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.