CVE-2026-29909

MEDIUM

MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-29909. PoCs published by SecureWithUmer, qflksheep.

AI-analyzed exploit summary The repository contains a minimal PoC for CVE-2026-29909, an unauthenticated directory enumeration vulnerability in MRCMS V3.1.2. The README describes the issue and provides a basic HTTP request to exploit the flaw but lacks functional exploit code or deeper technical analysis.

Description

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

Exploits (2)

github STUB
by SecureWithUmer · c++poc
https://github.com/SecureWithUmer/CVE-2026-PoCs/tree/main/2026/CVE-2026-29909

The repository contains a minimal PoC for CVE-2026-29909, an unauthenticated directory enumeration vulnerability in MRCMS V3.1.2. The README describes the issue and provides a basic HTTP request to exploit the flaw but lacks functional exploit code or deeper technical analysis.

Classification
Stub 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MRCMS V3.1.2
No auth needed
Prerequisites: Network access to the target server · MRCMS V3.1.2 deployed with the vulnerable endpoint exposed
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
nomisec WORKING POC
by qflksheep · poc
https://github.com/qflksheep/CVE-2026-29909-MRCMS-vulnerability

The repository provides a functional HTTP request PoC for CVE-2026-29909, demonstrating unauthenticated directory enumeration in MRCMS V3.1.2 via the /admin/file/list.do endpoint. The exploit leverages path traversal to access sensitive server directories without authentication.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MRCMS V3.1.2
No auth needed
Prerequisites: network access to the target server
mistral-large-3 · analyzed Apr 28, 2026 Full analysis →

Scores

CVSS v3 5.3
EPSS 0.0041
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-425
Status published
Products (2)
mrcms/mrcms 3.1.2
n/a/n/a
Published Mar 30, 2026
Tracked Since Mar 30, 2026