EIP-2026-100662

PRE-CVE

Sitecore - Remote Code Execution v8.2

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100662. PoCs published by abhishek morla.

AI-analyzed exploit summary This exploit leverages a deserialization vulnerability in Sitecore's XAML parser to execute arbitrary code by injecting a malicious payload via the `__PARAMETERS` field, leading to remote code execution (RCE). The payload uses ASP.NET controls to extract connection strings from the target system.

Description

Sitecore - Remote Code Execution v8.2

Exploits (1)

exploitdb WORKING POC
by abhishek morla · pythonwebappsaspx
https://www.exploit-db.com/exploits/51876

This exploit leverages a deserialization vulnerability in Sitecore's XAML parser to execute arbitrary code by injecting a malicious payload via the `__PARAMETERS` field, leading to remote code execution (RCE). The payload uses ASP.NET controls to extract connection strings from the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sitecore Experience Platform (versions 8.2, 9.0 to 10.3)
No auth needed
Prerequisites: Network access to the target Sitecore instance · Vulnerable `/sitecore_xaml.ashx` endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026