EIP-2026-100658

PRE-CVE

NopCommerce 4.2.0 - Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100658. PoCs published by Alessandro Magnosi.

AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in NopCommerce 4.2.0, allowing an authenticated attacker to upload a malicious .cshtml file via directory traversal in the RoxyFileman component, resulting in remote code execution (RCE). The PoC includes a fully functional web shell for command execution.

Description

NopCommerce 4.2.0 - Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by Alessandro Magnosi · pythonwebappsaspx
https://www.exploit-db.com/exploits/47783

This exploit targets a privilege escalation vulnerability in NopCommerce 4.2.0, allowing an authenticated attacker to upload a malicious .cshtml file via directory traversal in the RoxyFileman component, resulting in remote code execution (RCE). The PoC includes a fully functional web shell for command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NopCommerce 4.2.0
Auth required
Prerequisites: Valid credentials for NopCommerce admin panel · Access to the RoxyFileman component
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026