Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Automated-scanner-CVE-2026-41940 — Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection | Kitploit
Tools/GitHubGitHub/sardine-web/automated-scanner-cve-2026-41940
Authentication & AuthorizationReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPost-ExploitationPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Command and Control
Red Teaming
Payload Development
GitHubsardine-web/automated-scanner-cve-2026-41940

Automated-scanner-CVE-2026-41940

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

View Repository
1174 months agoNot yet reviewed

CPANEL CVE EXPLOIT

English | فارسی (Persian)

 ██████╗██████╗  █████╗ ███╗   ██╗███████╗██╗
██╔════╝██╔══██╗██╔══██╗████╗  ██║██╔════╝██║
██║     ██████╔╝███████║██╔██╗ ██║█████╗  ██║
██║     ██╔═══╝ ██╔══██║██║╚██╗██║██╔══╝  ██║
╚██████╗██║     ██║  ██║██║ ╚████║███████╗███████╗
 ╚═════╝╚═╝     ╚═╝  ╚═╝╚═╝  ╚═══╝╚══════╝╚══════╝

 ██████╗██╗   ██╗███████╗
██╔════╝██║   ██║██╔════╝
██║     ██║   ██║█████╗
██║     ╚██╗ ██╔╝██╔══╝
╚██████╗ ╚████╔╝ ███████╗
 ╚═════╝  ╚═══╝  ╚══════╝

███████╗██╗  ██╗██████╗ ██╗      ██████╗ ██╗████████╗
██╔════╝╚██╗██╔╝██╔══██╗██║     ██╔═══██╗██║╚══██╔══╝
█████╗   ╚███╔╝ ██████╔╝██║     ██║   ██║██║   ██║
██╔══╝   ██╔██╗ ██╔═══╝ ██║     ██║   ██║██║   ██║
███████╗██╔╝ ██╗██║     ███████╗╚██████╔╝██║   ██║
╚══════╝╚═╝  ╚═╝╚═╝     ╚══════╝ ╚═════╝ ╚═╝   ╚═╝

Python CVE CVSS License Stdlib

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection.


Table of Contents

  • Overview
  • CVE Details
  • How It Works
  • Features
  • Affected Versions
  • Requirements
  • Installation
  • Quick Start
  • Usage
  • Post-Exploit Actions
  • Interactive WHM Shell
  • Mass Scanning & Pipeline Integration
  • Shodan Dorks
  • Output Format
  • Example Session
  • Legal Disclaimer

Overview

CPANEL CVE EXPLOIT is a single-file Python tool designed for authorized security assessments of cPanel & WHM servers vulnerable to CVE-2026-41940.

The vulnerability allows an unauthenticated remote attacker to poison WHM session files through CRLF injection in the Authorization: Basic header, bypassing authentication and gaining root-level WHM access without valid credentials.

PropertyValue
CVECVE-2026-41940
SeverityCritical
CVSS10.0
Attack VectorNetwork / Unauthenticated
ImpactFull WHM root access
Default Port2087 (WHM)
StatusIn-the-wild exploitation confirmed (Apr 2026)

CVE Details

Root Cause

In vulnerable versions of cPanel & WHM, saveSession() in Session.pm calls filter_sessiondata() after writing the session file to disk. An attacker can inject CRLF (\r\n) characters through the HTTP Authorization: Basic header, which gets written directly into the on-disk session file — bypassing sanitization.

Injected Session Fields

The tool uses a Base64-encoded payload that decodes to:

root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1

These fields simulate a fully authenticated root WHM session, including 2FA bypass (tfa_verified=1) and root privilege flag (hasroot=1).

Fix

cPanel moved filter_sessiondata() to execute before the session write operation in Session.pm.


How It Works

The exploit chain consists of 5 stages (Stage 0–4):

flowchart TD
    A[Stage 0: Canonical Host Discovery] --> B[Stage 1: Mint Preauth Session]
    B --> C[Stage 2: CRLF Injection via Authorization Header]
    C --> D[Stage 3: Session Propagation via do_token_denied]
    D --> E[Stage 4: Verify Root Access via json-api/version]
    E --> F{Vulnerable?}
    F -->|Yes| G[Post-Exploit Actions / Interactive Shell]
    F -->|No| H[Skip Target]

    A -.- A1["GET /openid_connect/cpanelid → 307 redirect reveals real hostname"]
    B -.- B1["POST /login/?login_only=1 → whostmgrsession cookie"]
    C -.- C1["GET / + poisoned Basic auth → /cpsessXXXXXXXXXX token"]
    D -.- D1["GET /scripts2/listaccts → flush raw session to cache"]
    E -.- E1["GET /cpsessXXX/json-api/version → HTTP 200 + version JSON"]
StageEndpointPurpose
0/openid_connect/cpanelidAuto-discover canonical hostname via 307 redirect
1/login/?login_only=1Obtain preauth whostmgrsession cookie with wrong credentials
2/Inject CRLF-poisoned Authorization: Basic header into session file
3/scripts2/listacctsTrigger do_token_denied gadget to flush session to cache
4/{token}/json-api/versionConfirm root access — HTTP 200 with version JSON

Features

FeatureDescription
Single-target scanFull exploit chain against one WHM URL
Mass scanningMulti-threaded scanning from file or stdin
Version detectionAutomatic patched/vulnerable version comparison
Post-exploit APIPassword change, command exec, account listing, user creation
Interactive shellBuilt-in WHM root shell with file read & API commands
Selenium loginAuto-inject session cookie into Chrome/Firefox
Manual browser fallbackConsole JavaScript snippets for manual WHM login
RCE checkQuick id / uname -a verification after bypass
JSON exportSave all findings to structured JSON report
Pipeline-readyWorks with httpx, subfinder, shodan, and awk pipelines
Stdlib onlyNo pip dependencies required for core functionality
Colorized outputReal-time stage logging with severity indicators

Affected Versions

BranchPatched AtStatus
11.110.x11.110.0.97Vulnerable below patch
11.118.x11.118.0.63Vulnerable below patch
11.126.x11.126.0.54Vulnerable below patch
11.132.x11.132.0.29Vulnerable below patch
11.134.x11.134.0.20Vulnerable below patch
11.136.x11.136.0.5Vulnerable below patch

Note: Targets running patched builds are automatically flagged and skipped during scanning.


Requirements

Core (required)

  • Python 3.8+
  • No external packages — uses Python standard library only

Optional

PackagePurpose
seleniumBrowser auto-login (--selenium)
Chrome / FirefoxBrowser engine for Selenium
pip install -r requirements.txt   # optional — selenium only

Installation

git clone https://github.com/YOUR_USERNAME/cpanel-cve-exploit.git
cd cpanel-cve-exploit

No build step required. Run directly:

python3 test-cve.py --help

Quick Start

# Scan a single WHM target
python3 test-cve.py -u https://target.com:2087

# Scan with post-exploit: list all cPanel accounts
python3 test-cve.py -u https://target.com:2087 --action list

# Mass scan from file, 20 threads, save JSON report
python3 test-cve.py -l targets.txt -t 20 -o results.json

Usage

usage: test-cve.py [-h] [-u URL] [-l LIST] [--hostname HOSTNAME]
                   [-t THREADS] [--timeout TIMEOUT] [--rate-limit RATE_LIMIT]
Download Tool