EIP-2026-100736

PRE-CVE

Alkalay.Net (Multiple Scripts) - Remote Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100736. PoCs published by sullo@cirt.net.

AI-analyzed exploit summary The exploit demonstrates arbitrary command execution in multiple Alkalay.net CGI scripts due to improper input sanitization. Attackers can inject commands via the pipe character or semicolon in URL parameters, leading to remote code execution in the context of the web server.

Description

Alkalay.Net (Multiple Scripts) - Remote Command Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by sullo@cirt.net · textwebappscgi
https://www.exploit-db.com/exploits/26289

The exploit demonstrates arbitrary command execution in multiple Alkalay.net CGI scripts due to improper input sanitization. Attackers can inject commands via the pipe character or semicolon in URL parameters, leading to remote code execution in the context of the web server.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Alkalay.net CGI scripts (man-cgi, nslookup.cgi, contribute.pl, contribute.cgi)
No auth needed
Prerequisites: Access to vulnerable CGI scripts on the target server
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026