
Interactive exploitation tool for CVE-2026-41940
cPanel2Shell exploits a critical Authentication Bypass flaw in cPanel & WHM.
The vulnerability is caused by a CRLF injection in the login/session handling mechanism,
allowing an unauthenticated attacker to bypass authentication entirely — no password, no phishing.
If the target runs cPanel/WHM > v11.40 or WP Squared, it may be vulnerable.
🔴 CVSS Score: 9.8 (Critical) — Pre-auth, remotely exploitable
🌐 ~1.5 million cPanel instances exposed on the internet
For educational and authorized pentesting purposes only.
The author is not responsible for any misuse or damage caused by this tool.
git clone https://github.com/yurahshell/CVE-2026-41940
cd CVE-2026-41940
pip install -r requirements.txt
| Software | Affected Versions |
|---|---|
| cPanel & WHM | All versions after v11.40 |
| WP Squared | v136.1.7 and below |