
CVE-2026-55040-Mass-Exploit
Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

Exploit chain for unauthenticated RCE on Microsoft SharePoint, combining a JWT authentication bypass with unsafe .NET type instantiation to achieve…

Exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM, allowing unauthenticated attackers to gain root access via session injection and…

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

Proof-of-concept exploit for CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM using CRLF injection to leak security tokens and…

GNU telnetd service from GNU InetUtils authentication-bypass

Proof-of-concept exploit for Rack::Cookie authentication bypass (CVE-2026-39324), demonstrating session forgery via fallback coder to gain admin…

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt. Forges JWT tokens to gain admin access to protected endpoints.

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

Proof-of-concept exploit for CVE-2026-41940, a critical cPanel & WHM authentication bypass via session-file CRLF injection, enabling automatic root…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

While Fortinet's January 27, 2026 mitigation for **CVE-2026-24858** focuses on blocking specific accounts like `[email protected]`, it fails to…

Exploit for CVE-2026-7731 targeting cloud-native identity gateways by refracting JWT temporal validation to escalate privileges from admin:false to…

Exploit for CVE-2026-29000, a JWT authentication bypass in pac4j-jwt via JWE-wrapped PlainJWT, allowing token forgery and privilege escalation.

This Proof‑of‑Concept demonstrates a **Local Privilege Escalation** vulnerability in GNU inetutils `telnetd`. `telnetd` improperly passes…

CVE-2026-23760 - An authentication bypass via password reset API in SmarterMail.

Automated exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM, allowing unauthorized administrative access to vulnerable servers.

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…