Impact
An authentication bypass flaw in the cPanel and WHM login flow allows an unauthenticated remote attacker to gain control of the management console. The vulnerability exploits improper authentication checks (CWE-306), enabling attackers to obtain privileged access without valid credentials, thereby threatening the confidentiality, integrity, and availability of the hosted services.
Affected Systems
The flaw applies to cPanel and WHM. The CNA list also includes WP Squared, and no detailed affected-version information is available from the CVE narrative, so all three products are considered potentially vulnerable until version specifics are confirmed. The absence of explicit version data means administrators should assume higher risk for any recent releases.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score of 88% indicates an extremely high likelihood of exploitation, and the vulnerability is listed in the CISA KEV catalog, confirming that it has been actively exploited. The likely attack vector is the login flow (inferred), allowing an unauthenticated attacker to acquire an authenticated session without valid credentials. The KEV listing underscores the urgency, as vulnerable hosts remain at risk.
OpenCVE Enrichment