Evidence dossier

CVE-2026-41940

WebPros cPanel and WHM Authentication Bypass via Login Flow

Exploited in the wild (CISA KEV since Apr 30, 2026). VulnCheck reports CVSS 4.0 9.3. EPSS estimates 98.5% exploit likelihood as of Aug 27, 2026.

87.290.0Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

State
PUBLISHED
Published
Apr 29, 2026
Updated
Aug 4, 2026
Evidence coverage
97%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    VulnCheck

    Record text: WebPros cPanel and WHM Authentication Bypass via Login Flow

    Inspect raw assertion
    Field
    container
    Value
    WebPros cPanel and WHM Authentication Bypass via Login Flow
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 98.53% probability · 99.92th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.985270000000; percentile 0.999180000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Apr 30, 2026 · first observed Jul 19, 2026

Exploit likelihood98.53%

FIRST EPSS · score date Aug 27, 2026 · 99.9th percentile · first observed Aug 27, 2026

SeverityCVSS 9.3

VulnCheck · CVSS 4.0 · first observed Aug 4, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
VulnCheckOriginal assertion
Record text

WebPros cPanel and WHM Authentication Bypass via Login Flow

Inspect raw assertion
Field
container
Value
WebPros cPanel and WHM Authentication Bypass via Login Flow
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

98.53% probability · 99.92th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.985270000000; percentile 0.999180000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
19Underlying assertions
3Canonical products
19Target assertions
0Constraint assertions

Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

6 scope groups

VulnCheck · source assertedWebProscPanelDirect source scope
Affected: 11.40.0.0 to before 11.86.0.41 (custom comparison)Affected: 11.88.0.0 to before 11.94.0.28 (custom comparison)Affected: 11.96.0.0 to before 11.102.0.39 (custom comparison)Affected: 11.104.0.0 to before 11.110.0.97 (custom comparison)Affected: 11.112.0.0 to before 11.118.0.63 (custom comparison)Affected: 11.120.0.0 to before 11.124.0.35 (custom comparison)Affected: 11.126.0.0 to before 11.126.0.54 (custom comparison)Affected: 11.128.0.0 to before 11.130.0.19 (custom comparison)Affected: 11.132.0.0 to before 11.132.0.29 (custom comparison)Affected: 11.134.0.0 to before 11.134.0.20 (custom comparison)Affected: 11.136.0.0 to before 11.136.0.5 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "11.40.0.0", "lessThan": "11.86.0.41", "versionType": "custom"}, {"status": "affected", "version": "11.88.0.0", "lessThan": "11.94.0.28", "versionType": "custom"}, {"status": "affected", "version": "11.96.0.0", "lessThan": "11.102.0.39", "versionType": "custom"}, {"status": "affected", "version": "11.104.0.0", "lessThan": "11.110.0.97", "versionType": "custom"}, {"status": "affected", "version": "11.112.0.0", "lessThan": "11.118.0.63", "versionType": "custom"}, {"status": "affected", "version": "11.120.0.0", "lessThan": "11.124.0.35", "versionType": "custom"}, {"status": "affected", "version": "11.126.0.0", "lessThan": "11.126.0.54", "versionType": "custom"}, {"status": "affected", "version": "11.128.0.0", "lessThan": "11.130.0.19", "versionType": "custom"}, {"status": "affected", "version": "11.132.0.0", "lessThan": "11.132.0.29", "versionType": "custom"}, {"status": "affected", "version": "11.134.0.0", "lessThan": "11.134.0.20", "versionType": "custom"}, {"status": "affected", "version": "11.136.0.0", "lessThan": "11.136.0.5", "versionType": "custom"}]
VulnCheck · source assertedWebProsWHMDirect source scope
Affected: 11.40.0.0 to before 11.86.0.41 (custom comparison)Affected: 11.88.0.0 to before 11.94.0.28 (custom comparison)Affected: 11.96.0.0 to before 11.102.0.39 (custom comparison)Affected: 11.104.0.0 to before 11.110.0.97 (custom comparison)Affected: 11.112.0.0 to before 11.118.0.63 (custom comparison)Affected: 11.120.0.0 to before 11.124.0.35 (custom comparison)Affected: 11.126.0.0 to before 11.126.0.54 (custom comparison)Affected: 11.128.0.0 to before 11.130.0.19 (custom comparison)Affected: 11.132.0.0 to before 11.132.0.29 (custom comparison)Affected: 11.134.0.0 to before 11.134.0.20 (custom comparison)Affected: 11.136.0.0 to before 11.136.0.5 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "11.40.0.0", "lessThan": "11.86.0.41", "versionType": "custom"}, {"status": "affected", "version": "11.88.0.0", "lessThan": "11.94.0.28", "versionType": "custom"}, {"status": "affected", "version": "11.96.0.0", "lessThan": "11.102.0.39", "versionType": "custom"}, {"status": "affected", "version": "11.104.0.0", "lessThan": "11.110.0.97", "versionType": "custom"}, {"status": "affected", "version": "11.112.0.0", "lessThan": "11.118.0.63", "versionType": "custom"}, {"status": "affected", "version": "11.120.0.0", "lessThan": "11.124.0.35", "versionType": "custom"}, {"status": "affected", "version": "11.126.0.0", "lessThan": "11.126.0.54", "versionType": "custom"}, {"status": "affected", "version": "11.128.0.0", "lessThan": "11.130.0.19", "versionType": "custom"}, {"status": "affected", "version": "11.132.0.0", "lessThan": "11.132.0.29", "versionType": "custom"}, {"status": "affected", "version": "11.134.0.0", "lessThan": "11.134.0.20", "versionType": "custom"}, {"status": "affected", "version": "11.136.0.0", "lessThan": "11.136.0.5", "versionType": "custom"}]
VulnCheck · source assertedWebProsWP SquaredDirect source scope
Unaffected: 11.136.1.7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "11.136.1.7", "versionType": "custom"}]
NVD CPE · APPLICATIONcpanelcpanelVulnerable target · 9 assertions
Any version (unconstrained) (>= 112.0.0, < 118.0.63); Any version (unconstrained) (>= 11.40, < 86.0.41); Any version (unconstrained) (>= 120.0.0, < 124.0.35); Any version (unconstrained) (>= 126.0.1, < 126.0.54); Any version (unconstrained) (>= 128.0.0, < 130.0.19); Any version (unconstrained) (>= 132.0.0, < 132.0.29); Any version (unconstrained) (>= 134.0.0, < 134.0.20); Any version (unconstrained) (>= 136.0.0, < 136.0.5); Any version (unconstrained) (>= 88.0.0, < 110.0.97)Canonical identity product-af183c6f83b2ae13a2bf7583a6bacfebaeab3a8b2910c7572f753d73d7e31fdfLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    from including 134.0.0; through excluding 134.0.20
    Match ID
    b0213a2b-4a5a-4098-87ff-517e33f96807
  2. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 11.40; through excluding 86.0.41
    Match ID
    d018d47f-b020-41b1-8755-9197eb8673d3
  3. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 132.0.0; through excluding 132.0.29
    Match ID
    24982921-6c0d-478e-bbf1-7c9dc7023760
  4. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 126.0.1; through excluding 126.0.54
    Match ID
    15c0513d-8c56-4c5f-b818-e2ce90223ad4
  5. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    from including 136.0.0; through excluding 136.0.5
    Match ID
    09f99f08-1fb9-4bc6-8c7d-52062ba28479
  6. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 88.0.0; through excluding 110.0.97
    Match ID
    9bf3dbac-d629-44a9-b102-2d8f82709ca2
  7. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 120.0.0; through excluding 124.0.35
    Match ID
    5533aa73-5007-4820-a5c6-0460c486882d
  8. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 128.0.0; through excluding 130.0.19
    Match ID
    b5fe32ec-aefb-4b27-ae65-a95432caa812
  9. cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 112.0.0; through excluding 118.0.63
    Match ID
    3eeff12c-11e8-4a5c-9c72-ba1a422a9e72
NVD CPE · APPLICATIONcpanelwhmVulnerable target · 9 assertions
Any version (unconstrained) (>= 112.0.0, < 118.0.63); Any version (unconstrained) (>= 11.40, < 86.0.41); Any version (unconstrained) (>= 120.0.0, < 124.0.35); Any version (unconstrained) (>= 126.0.1, < 126.0.54); Any version (unconstrained) (>= 128.0.0, < 130.0.19); Any version (unconstrained) (>= 132.0.0, < 132.0.29); Any version (unconstrained) (>= 134.0.0, < 134.0.20); Any version (unconstrained) (>= 136.0.0, < 136.0.5); Any version (unconstrained) (>= 88.0.0, < 110.0.97)Canonical identity product-a0f73021ccf6fcfa7af9ac9e29353bc76789562b23407a7daa8a6a23c5c43b54Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 11.40; through excluding 86.0.41
    Match ID
    63be6def-a6ea-4545-9a3d-e1ba84a50ec7
  2. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 120.0.0; through excluding 124.0.35
    Match ID
    2ed81103-d03e-4351-9c19-1b3f120268d6
  3. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 112.0.0; through excluding 118.0.63
    Match ID
    2fcd52cf-3f10-4ffa-8fc7-aa5f370af9b8
  4. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 128.0.0; through excluding 130.0.19
    Match ID
    c6c216f5-330d-4daa-b042-1a4707ff658e
  5. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    from including 134.0.0; through excluding 134.0.20
    Match ID
    53ac31a0-ad91-4897-89e7-1c05af03bf5a
  6. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 132.0.0; through excluding 132.0.29
    Match ID
    8793eed8-bdbd-4cc8-9698-fcee769cfb5b
  7. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 126.0.1; through excluding 126.0.54
    Match ID
    6dc3d6f0-8d07-4719-977e-db978aeb7a67
  8. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    from including 136.0.0; through excluding 136.0.5
    Match ID
    23d646d3-2bdc-44c8-8c5f-9e21b0613a48
  9. cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 88.0.0; through excluding 110.0.97
    Match ID
    74e9c069-ea63-4b95-9229-45ad97563532
NVD CPE · APPLICATIONcpanelwp_squaredVulnerable target · 1 assertions
Any version (unconstrained) (< 136.1.7)Canonical identity product-9efdf7ec6f25bb0430b2615c3464dd75487e54c0224f5462424069bddc36e88aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 136.1.7
    Match ID
    80392939-b45d-4c12-adbb-334e783bde67

Affected-product evidence

Accepted scope and product mapping

3 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-f45d5d1c071d5abb7dfc5611355400e0e0ca7acd39582c191c8483f1be4a756a · product-9efdf7ec6f25bb0430b2615c3464dd75487e54c0224f5462424069bddc36e88a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3a466663-a4c5-42ab-9362-4150346a606a
Mapping establishedEvidence supported

vendor-f45d5d1c071d5abb7dfc5611355400e0e0ca7acd39582c191c8483f1be4a756a · product-a0f73021ccf6fcfa7af9ac9e29353bc76789562b23407a7daa8a6a23c5c43b54

Source class
Nvd cpe vulnerable target
Assertions
9
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
36d0cbf1-c70a-49a6-aebe-3445a1ac96f0476cf790-d155-4602-afe9-c789aae590e848530117-5abd-40e6-bb24-5cc90f7047d47673419c-35e7-40c1-958a-4d8216dcb9fba85749fb-3725-4c82-8d53-48ef723db309ad100338-b1ac-452d-8eed-8364201a0840dda328ac-6f74-48e2-95cb-7e298ee64b5cddd8ebd3-942a-4d9b-933e-8492e53a8868fceda9be-698a-446a-a4fd-7d50db4b7e57
Mapping establishedEvidence supported

vendor-f45d5d1c071d5abb7dfc5611355400e0e0ca7acd39582c191c8483f1be4a756a · product-af183c6f83b2ae13a2bf7583a6bacfebaeab3a8b2910c7572f753d73d7e31fdf

Source class
Nvd cpe vulnerable target
Assertions
9
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
38638c28-7f7e-41dc-9f85-d516ee7ba9ad3da9b9ee-e68d-42a7-8e33-f4d07f689877470c31d0-4a20-4c00-a5d3-e14c960fa489843070d4-160d-4999-99fa-2c7a6e5c483adeb761aa-6011-46d2-8904-33e833188cdfe76524ab-74b3-48d1-9acb-61839f840f4cef798078-d11a-4040-87fb-9d0a017e2854f907e4a7-37e6-4fc2-aadc-a7d3c70c7e44faa7bcd5-f35b-4ef5-a6b2-eb227c35b5ed
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a0d34aea-7164-4b07-bdd6-ea6ff69a6550a16a68bd-1872-4e27-9920-38bab9a84d14fb64407f-a4bd-4aca-bc74-14ecbf867cef

Assessments

CVSS by origin

9.3
disclosure@vulncheck.comCVSS 4.0 · role Secondary · priority eligiblevalid_matchCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9.8
disclosure@vulncheck.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3
VulnCheckCVSS 4.0 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
9.8
VulnCheckCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.3Priority eligible

VulnCheck

CVSS 4.0 · Primary · Original assertion · rank 1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Validation
Valid match
Recomputed
9.3
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1
9.8Priority eligible

VulnCheck

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.