EIP-2026-100098

PRE-CVE

Acuity CMS 2.6.2 - '/admin/file_manager/browse.asp?path' Traversal Arbitrary File Access

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100098. PoCs published by Aung Khant.

AI-analyzed exploit summary The provided text describes a directory traversal and arbitrary file upload vulnerability in Acuity CMS 2.6.2. It includes a sample URL demonstrating the traversal but lacks executable exploit code.

Description

Acuity CMS 2.6.2 - '/admin/file_manager/browse.asp?path' Traversal Arbitrary File Access

Exploits (1)

exploitdb WRITEUP VERIFIED
by Aung Khant · textwebappsasp
https://www.exploit-db.com/exploits/37223

The provided text describes a directory traversal and arbitrary file upload vulnerability in Acuity CMS 2.6.2. It includes a sample URL demonstrating the traversal but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Acuity CMS 2.6.2
No auth needed
Prerequisites: Network access to the target · Acuity CMS installation with vulnerable file manager
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026