{"repo":"Kill1234545/CVE-2026-41940","free":true,"listed":false,"github":"https://github.com/Kill1234545/CVE-2026-41940","clone":"git clone https://github.com/Kill1234545/CVE-2026-41940.git","description":"cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)","language":"Python","stars":10,"topics":["authentication","bypasser","cpanel","cve-2026-41940","poc","python","shell","whm","zero-day"],"license":null,"category":"auth-billing-email","readme_excerpt":"CVE-2026-41940: cPanel/WHM Authentication Bypass (Single & Multi-Target) Disclaimer: This document and the associated script ( exploit.py ) are provided strictly for educational purposes, security research, and authorized penetration testing. Do not use this software against systems you do not own or do not have explicit permission to test. Overview exploit.py is a script that demonstrates an authentication bypass vulnerability (CVE-2026-41940) in cPanel & WHM. The vulnerability allows an unauthenticated attacker to inject a root session into the daemon cache via a CRLF injection flaw, ultimately granting root-level WHM access without requiring valid credentials. Vulnerability Analysis & Exploit Flow The exploit works by leveraging a CRLF (Carriage Return Line Feed) injection vulnerability within the Basic Authentication handling mechanism, combined with a session propagation flaw. The script automates the attack in four stages: 1. Pre-Auth Session Minting: Connects to public login endpoints (e.g., /login/ or /cgi/login.cgi ) to acquire a baseline unauthenticated session cookie ( whostmgrsession ). 2. CRLF Injection: Sends a crafted Basic Authentication header containing a Base64-encoded payload that injects root session fields directly into the cpsrvd session cache. The server's redirect response leaks the generated security token ( cpsess ). 3. Session Propagation: The raw session cookie is sent to an authenticated WHM endpoint, triggering do token denied to propagate the f","default_branch":null,"files":null,"tree":[],"storefront":"/r/Kill1234545","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Kill1234545/CVE-2026-41940/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}