EIP-2026-100016
PRE-CVEOPMANAGER - Blind SQL Injection / XPath Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100016. PoCs published by Asheesh kumar Mani Tripathi.
AI-analyzed exploit summary This is a technical writeup describing a blind SQL/XPath injection vulnerability in OPMANAGER. It includes a vulnerable URL, a crafted HTTP request demonstrating the injection, and a brief explanation of the vulnerability's impact.
Description
OPMANAGER - Blind SQL Injection / XPath Injection
Exploits (1)
exploitdb
WRITEUP
by Asheesh kumar Mani Tripathi · textwebappsaix
https://www.exploit-db.com/exploits/10372
This is a technical writeup describing a blind SQL/XPath injection vulnerability in OPMANAGER. It includes a vulnerable URL, a crafted HTTP request demonstrating the injection, and a brief explanation of the vulnerability's impact.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target:
ManageEngine OPMANAGER (version not specified)
No auth needed
Prerequisites:
Network access to the target application
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026