EIP-2026-102467

PRE-CVE

CA ARCserve D2D r15 GWT RPC - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102467. PoCs published by rgod.

AI-analyzed exploit summary This PHP script demonstrates an authentication bypass and credentials disclosure vulnerability in CA ARCserve D2D r15 via a crafted GWT RPC request. It exploits a lack of session validation for localhost-originating requests to retrieve Windows Administrator credentials in cleartext.

Description

CA ARCserve D2D r15 GWT RPC - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsjsp
https://www.exploit-db.com/exploits/17574

This PHP script demonstrates an authentication bypass and credentials disclosure vulnerability in CA ARCserve D2D r15 via a crafted GWT RPC request. It exploits a lack of session validation for localhost-originating requests to retrieve Windows Administrator credentials in cleartext.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: CA ARCserve D2D r15
No auth needed
Prerequisites: Network access to port 8014 on the target · Tomcat service running with default configuration
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026