EIP-2026-102495

PRE-CVE

ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet - Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102495. PoCs published by rgod.

AI-analyzed exploit summary This exploit leverages an unauthenticated directory traversal vulnerability in ManageEngine DeviceExpert 5.6's ScheduleResultViewer servlet to disclose arbitrary files, including authentication credentials and database backups. The PoC demonstrates file retrieval via crafted HTTP requests to the servlet.

Description

ManageEngine DeviceExpert 5.6 Java Server ScheduleResultViewer servlet - Directory Traversal

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · textwebappsjsp
https://www.exploit-db.com/exploits/18626

This exploit leverages an unauthenticated directory traversal vulnerability in ManageEngine DeviceExpert 5.6's ScheduleResultViewer servlet to disclose arbitrary files, including authentication credentials and database backups. The PoC demonstrates file retrieval via crafted HTTP requests to the servlet.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ManageEngine DeviceExpert 5.6
No auth needed
Prerequisites: Network access to port 6060 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026