Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2815+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug
cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug
NEWS

cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

cPanel and WebHost Manager have released an emergency patch for a critical authentication bypass vulnerability that allows attackers to gain control panel...

Dylan H.

News Desk

April 29, 2026
3 min read

Emergency Patch Released

cPanel has issued an emergency out-of-band security update addressing a critical authentication bypass vulnerability affecting all versions of the cPanel and WebHost Manager (WHM) control panel prior to the latest release. The flaw could be exploited by unauthenticated remote attackers to gain unauthorized access to the web hosting control panel — one of the most widely deployed hosting management platforms globally.

The vulnerability is rated critical due to its low attack complexity and the complete loss of access control it enables. Because cPanel and WHM power millions of shared hosting environments, the blast radius of exploitation is significant.

What Is cPanel & WHM?

cPanel is the industry-standard web hosting control panel used by hosting providers worldwide to manage websites, email accounts, databases, DNS, and server configurations. WHM (WebHost Manager) is the reseller and server administrator interface layered on top.

Hosting providers, web agencies, and enterprises running self-managed hosting infrastructure rely heavily on these tools, making critical flaws in cPanel a high-priority target for attackers seeking to compromise large numbers of websites and customer accounts in a single operation.

Vulnerability Details

The authentication bypass allows an attacker to obtain access to a cPanel or WHM account without providing valid credentials. Based on the nature of the disclosure, the flaw likely resides in the session validation or token verification logic used by cPanel's API or web interface.

Key characteristics of the vulnerability:

  • Authentication requirement: None — the vulnerability is pre-authentication
  • Attack complexity: Low — can be exploited without specialized knowledge
  • Privileges required: None — no prior access needed
  • Scope: Full control panel access, including file manager, email, databases, and server configuration
  • Affected versions: All versions prior to the emergency patch release

Successful exploitation could give attackers the ability to:

  • Access, modify, or delete all website files hosted on the server
  • Read sensitive configuration files, database credentials, and email
  • Create new administrative accounts for persistent access
  • Deploy web shells or malware to hosted websites
  • Reconfigure DNS to redirect web traffic or intercept email

Who Is Affected

Any hosting provider or system administrator running an unpatched version of cPanel or WHM is at risk. Given the widespread deployment of these tools — cPanel is reported to run on hundreds of thousands of servers — the potential attack surface is enormous.

Shared hosting environments are at particular risk, as a single compromised WHM instance can expose thousands of customer accounts hosted on the same server.

Remediation

cPanel has released an emergency update and strongly urges all users to apply it immediately:

  1. Update cPanel/WHM to the latest version via the update interface or by running /scripts/upcp on the server
  2. Review server access logs for any suspicious authentication attempts or anomalous session activity prior to patching
  3. Audit user accounts — check for any newly created accounts that were not authorized
  4. Enable two-factor authentication (2FA) on all administrative accounts as a defense-in-depth measure
  5. Restrict WHM access by IP address if remote access is not needed from all locations

References

  • BleepingComputer: cPanel, WHM emergency update fixes critical auth bypass bug
  • cPanel Security Advisories

Related Reading

  • Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now
  • Exploit Frenzy Threatens Millions via Critical cPanel
  • cPanel & WHM Release Fixes for Three New Vulnerabilities
#Vulnerability#cPanel#authentication#Web Hosting#Security Updates

Related Articles

cPanel & WHM Release Fixes for Three New Vulnerabilities

cPanel has released security updates addressing three vulnerabilities in cPanel and Web Host Manager (WHM), including flaws enabling privilege escalation,...

3 min read

Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now

The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been...

4 min read

Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

A newly disclosed critical vulnerability in cPanel and WHM tracked as CVE-2026-41940 is being mass-exploited by ransomware actors to breach web hosting...

5 min read
Back to all News