
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.
Critical unauthenticated RCE in cPanel & WHM. Four HTTP requests forge a root session via CRLF injection into the password field of a preauth session. No auth, no preconditions, every supported tier affected. Disclosed 2026-04-28 by Sina Kheirkhah / watchTowr Labs.
Quickstart · ioc-scan · mitigate · remote-probe · Affected builds · Priority order
[!IMPORTANT] Tiers 112, 114, 116, 120, 122, 128 have no vendor patch. Every build on those tiers is vulnerable; upgrade or migrate is the only durable fix. Until then: firewall TCP/2082, 2083, 2086, 2087, 2095, 2096 to management CIDRs (
mitigate.sh --applydoes this) and front the remaining surface with the ModSec rule pack.
Three oneliners, in operator priority order:
# 1. Are we already compromised? (on-host IOC scan, fast triage)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash
# 2. Close the window (idempotent; firewalls cpsrvd ports, deploys ModSec, etc.)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-mitigate.sh | bash -s -- --apply
# 3. Sweep the fleet from anywhere (non-destructive remote verdict)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-remote-probe.sh | bash -s -- --target HOST
Exit codes are designed for fleet automation: ioc-scan exits 4 on
COMPROMISED, 1 on VULNERABLE; mitigate exits 0 clean / 1 applied
/ 2 manual / 3 tool error; remote-probe exits 2 if any target is
VULN.
In order of operational priority. Every artifact emits structured output
(--json / --jsonl / --csv) keyed on host, os, cpanel_version,
ts for fleet roll-up.
| Tool | Role | Where it runs |
|---|---|---|
sessionscribe-ioc-scan.sh | First-class triage. IOC ladder, code-state + host-state verdicts, kill-chain reconstruction, IR bundle. | on the cPanel host |
sessionscribe-mitigate.sh | Close the window. Phased mitigation: patch check, firewall, proxysub, ModSec. | on the cPanel host |
sessionscribe-remote-probe.sh | Supporting collateral. Non-destructive 4-stage probe → VULN/SAFE per host. | anywhere with curl |
modsec-sessionscribe.conf | ModSec rule pack deployed by mitigate. | Apache front-end |
sessionscribe-revsnap.sh | Per-tier RE snapshot collector for binary diffing. | on the cPanel host, around upcp |
GPL v2. All artifacts curl-ready via the raw URLs above.
sessionscribe-ioc-scan.sh - IOC ladder + kill-chainRun this first. Detection-only by default (fast, fleet-friendly);
add --full to run the forensic phases inline (defense timeline, offense
ingest, reconcile, kill-chain renderer, IR bundle).
# fast triage (detection only)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash
# full kill-chain reconstruction inline
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --full
# full + ship IR bundle to intake
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --full --upload
# JSONL for SIEM ingest
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --jsonl --quiet > host.jsonl
# host IOCs only - periodic post-patch sweep, last 7 days
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --ioc-only --since 7
# replay forensic phases against a saved envelope (no re-scan)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --replay /var/cpanel/sessionscribe-ioc/<run_id>.json
Two axes report independently. code_verdict (PATCHED /
VULNERABLE / INCONCLUSIVE) comes from version, Perl source patterns,
and cpsrvd binary fingerprint. host_verdict (CLEAN /
SUSPICIOUS / COMPROMISED) comes from the session-file IOC ladder,
access-log scan, and Patterns A–G destruction probes. A patched host
can still exit 4 if prior exploitation left IOCs on disk.
| Exit | Code-state | Host-state | Triage action |
|---|---|---|---|
| 0 | CLEAN/PATCHED | CLEAN | none |
| 1 | VULNERABLE | (any) | patch cpsrvd |
| 2 | INCONCLUSIVE | (any) | manual code-state review (also: tool error) |
| 3 | (any) | SUSPICIOUS | review session/access logs |
| 4 | (any) | COMPROMISED | full IR; bundle + upload |
Sessions tagged with nxesec_canary_<nonce> (left by the remote probe)
bucket as PROBE_ARTIFACT and do not escalate to COMPROMISED.
--full collates every IOC against defense activations and classifies
each as PRE-DEFENSE, POST-DEFENSE, POST-PARTIAL, or
UNDEFENDED, then summarises with verdict + defense-lag headline.
PRE-DEFENSE = host was open to the exploit when the indicator landed;
POST-DEFENSE = collateral or pre-mitigation noise.
+-- CVE-2026-41940 / IC-5790 --------------------------------------------
| host cpanel.example.com ()
| cpanel unknown os unknown
| verdict COMPROMISED score 315 ioc-scan v2.5.0
| defenses patch x absent modsec + up csf + clean mitigate + ran
+------------------------------------------------------------------------
| -- PRE-DEFENSE (32 events) --
| 2026-03-25T09:43:19Z ! pattern X ioc_attacker_ip_2xx_on_cpsess 57 hit(s) (last 90d) from IC-5790 IPs returned 2xx on /cpsess<N>/ paths - real exploitation
| 2026-04-28T14:35:56Z ! pattern X ioc_cve_2026_41940_crlf_access_chain 15 CRLF-bypass chain(s) — POST /login 401 then GET /cpsess<N> 2xx as root within 2s
| 2026-04-28T16:38:45Z ! pattern E ioc_pattern_e_websocket_shell_hits 45 external IP(s) reached /cpsess*/websocket/Shell with 2xx
| 2026-04-29T08:41:22Z ! pattern F ioc_pattern_f_smark_envelope __S_MARK__/__E_MARK__ harvester envelope in /root/.bash_history
| 2026-04-29T16:41:24Z ! pattern A ioc_pattern_a_ransom_readme /home/user1/README.md
| … (22 more Pattern A ransom_readme events across customer homedirs)
| 2026-04-29T16:42:09Z ! pattern A ioc_pattern_a_sorry_files_present 608 .sorry-encrypted files present
| 2026-04-29T17:52:58Z ! pattern D ioc_pattern_d_acctlog_encrypted /var/cpanel/accounting.log.sorry