Alapadatok
Súlyosság: Kritikus
CVSS vektor: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS base score: 9.8
Kihasználhatóság:
- Hálózatról kihasználható
- Alacsony komplexitás
- Nem szükséges jogosultság
- Nem szükséges felhasználói interakció
Következmények
Other (Egyéb)
Publikálás dátuma: 2026.05.04.
Leírás
A szoftver nem végez semmilyen hitelesítést olyan funkcionalitáshoz, amely bizonyítható felhasználói azonosítót igényel, vagy jelentős mennyiségű erőforrást fogyaszt.
Leírás forrása: CWE-306
Érintett rendszerek és verzióik
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 11.40 Up to (excluding) 86.0.41
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 88.0.0 Up to (excluding) 110.0.97
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 112.0.0 Up to (excluding) 118.0.63
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 120.0.0 Up to (excluding) 126.0.54
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 128.0.0 Up to (excluding) 130.0.19
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 132.0.0 Up to (excluding) 132.0.29
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 134.0.0 Up to (excluding) 134.0.20
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* From (including) 136.0.0 Up to (excluding) 136.0.5
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 11.40 Up to (excluding) 86.0.41
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 88.0.0 Up to (excluding) 110.0.97
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 112.0.0 Up to (excluding) 118.0.63
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 120.0.0 Up to (excluding) 126.0.54
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 128.0.0 Up to (excluding) 130.0.19
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 132.0.0 Up to (excluding) 132.0.29
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 134.0.0 Up to (excluding) 134.0.20
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* From (including) 136.0.0 Up to (excluding) 136.0.5
cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:* Up to (excluding) 136.1.7
Hivatkozások
https://docs.cpanel.net/release-notes/release-notes
https://docs.wpsquared.com/changelogs/versions/changelog/#13617
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
