EIP-2026-102467
PRE-CVECA ARCserve D2D r15 GWT RPC - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102467. PoCs published by rgod.
AI-analyzed exploit summary This PHP script demonstrates an authentication bypass and credentials disclosure vulnerability in CA ARCserve D2D r15 via a crafted GWT RPC request. It exploits a lack of session validation for localhost-originating requests to retrieve Windows Administrator credentials in cleartext.
Description
CA ARCserve D2D r15 GWT RPC - Multiple Vulnerabilities
Exploits (1)
This PHP script demonstrates an authentication bypass and credentials disclosure vulnerability in CA ARCserve D2D r15 via a crafted GWT RPC request. It exploits a lack of session validation for localhost-originating requests to retrieve Windows Administrator credentials in cleartext.