EIP-2026-102354
PRE-CVEApache Flink 1.9.x - File Upload RCE (Unauthenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102354. PoCs published by bigger.wing.
AI-analyzed exploit summary This exploit targets an unauthenticated file upload vulnerability in Apache Flink 1.9.x, allowing remote code execution by uploading a malicious JAR file and executing arbitrary commands. The PoC includes methods for version detection, JAR upload, command execution, and cleanup.
Description
Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
Exploits (1)
This exploit targets an unauthenticated file upload vulnerability in Apache Flink 1.9.x, allowing remote code execution by uploading a malicious JAR file and executing arbitrary commands. The PoC includes methods for version detection, JAR upload, command execution, and cleanup.