Dismissed
(not in Nixpkgs)
Permalink
CVE-2026-41940
9.8 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
cPanel and WHM Authentication Bypass via Login Flow
cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
References
-
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security… vendor-advisorypatch
-
https://docs.cpanel.net/release-notes/release-notes release-notes
-
https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerabilit… third-party-advisory
-
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-l… third-party-advisory
Affected products
WHM
- <11.136.0.5
- <11.126.0.54
- <11.132.0.29
- <11.134.0.20
- <11.118.0.63
- <11.110.0.97
cPanel
- <11.136.0.5
- <11.126.0.54
- <11.132.0.29
- <11.134.0.20
- <11.118.0.63
- <11.110.0.97
WP Squared
- <11.136.1.7
Matching in nixpkgs
pkgs.perlPackages.CpanelJSONXS
CPanel fork of JSON::XS, fast and correct serializing
pkgs.perl5Packages.CpanelJSONXS
CPanel fork of JSON::XS, fast and correct serializing
pkgs.perl538Packages.CpanelJSONXS
CPanel fork of JSON::XS, fast and correct serializing
pkgs.perl540Packages.CpanelJSONXS
CPanel fork of JSON::XS, fast and correct serializing