CVE-2021-26705

CRITICAL

SquareBox CatDV < 9.2 - Unauthenticated Sensitive RMI Method Invocation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-26705. PoCs published by Christopher Ellis.

AI-analyzed exploit summary This exploit demonstrates an RMI authentication bypass in CatDV 9.2 by dumping existing connections and creating a new client session to retrieve user information. It leverages exposed RMI methods to bypass authentication and extract sensitive data.

Description

An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.

Exploits (1)

exploitdb WORKING POC
by Christopher Ellis · javaremotejava
https://www.exploit-db.com/exploits/49621

This exploit demonstrates an RMI authentication bypass in CatDV 9.2 by dumping existing connections and creating a new client session to retrieve user information. It leverages exposed RMI methods to bypass authentication and extract sensitive data.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: CatDV Server 9.2 and lower
No auth needed
Prerequisites: Access to RMI interface on port 1099 · CatDV Server running and exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49621

Scores

CVSS v3 9.1
EPSS 0.0048
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-306
Status published
Products (1)
squarebox/catdv < 9.2
Published Mar 05, 2021
Tracked Since Feb 18, 2026