:

CPANEL AND WHM AUTHENTICATION BYPASS DISCOVERED

SECURITY DESK2 MIN READ
FRI, MAY 1, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A critical authentication bypass vulnerability has been identified in cPanel and WHM, allowing attackers to gain unauthorized access to hosting control panels. The flaw, tracked as CVE-2026-41940, affects a widely used hosting management platform.

Security researchers at Watchtowr Labs have disclosed CVE-2026-41940, an authentication bypass vulnerability in cPanel and WHM (Web Host Manager). The flaw enables attackers to circumvent login mechanisms and access administrative functions without valid credentials. CPanel and WHM are industry-standard control panels used by hosting providers and website administrators to manage servers, domains, and hosting accounts. The authentication bypass represents a significant security risk given the platform's widespread adoption and the sensitive nature of the data it protects. ■ Technical Details The vulnerability allows attackers to bypass authentication checks through a flaw in the platform's request validation logic. Full technical analysis is available in the Watchtowr Labs report, which details the attack vector and proof-of-concept demonstrations. ■ Impact Successful exploitation could grant attackers: - Access to hosting control panels - Ability to modify server configurations - Control over hosted domains and accounts - Potential lateral movement across infrastructure The vulnerability affects multiple versions of cPanel and WHM, making it broadly relevant across the hosting industry. ■ Response CPanel has been notified of the vulnerability. Users are advised to: - Monitor official cPanel security announcements for patches - Implement network-level access controls to WHM interfaces - Review access logs for suspicious authentication attempts - Consider restricting WHM access to known IP addresses The disclosure has garnered significant attention in the security community, with 38 comments on Hacker News discussing implications and remediation strategies. Hosting providers should prioritize patching systems once updates become available. The vulnerability's authentication-bypass nature makes it particularly critical, as it undermines fundamental security controls.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Americans are systematically targeting and disabling Flock Safety cameras across the country in a decentralized protest movement. The surveillance devices face everything from vandalism to theft as public opposition intensifies.

2H AGOIndustry Desk

The US Justice Department has dismantled online infrastructure used by Chinese state-sponsored hackers targeting NASA, the Federal Reserve, and the Senate. The action represents a coordinated effort to disrupt cyber operations against American government agencies and critical infrastructure.

2H AGOSecurity Desk

The U.S. Cybersecurity and Infrastructure Security Agency has issued a mandate requiring all federal agencies to patch an actively exploited remote code execution vulnerability in Citrix NetScaler appliances by Saturday.

12H AGOSecurity Desk

A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.

23H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.