EIP-2026-102404
PRE-CVEManageEngine Exchange Reporter Plus < Build 5311 - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102404. PoCs published by Kacper Szurek.
AI-analyzed exploit summary This exploit targets ManageEngine Exchange Reporter Plus <= 5310 by leveraging an unauthenticated RCE vulnerability in the `ADSHACluster` servlet. It sends a crafted request with a hex-encoded executable payload via the `BCP_EXE` parameter to execute arbitrary commands.
Description
ManageEngine Exchange Reporter Plus < Build 5311 - Remote Code Execution
Exploits (1)
This exploit targets ManageEngine Exchange Reporter Plus <= 5310 by leveraging an unauthenticated RCE vulnerability in the `ADSHACluster` servlet. It sends a crafted request with a hex-encoded executable payload via the `BCP_EXE` parameter to execute arbitrary commands.