EIP-2026-102502
PRE-CVEManageEngine ServiceDesk Plus 9.1 build 9110 - Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102502. PoCs published by xistence.
AI-analyzed exploit summary This is a technical writeup detailing an unauthenticated path traversal vulnerability in ManageEngine ServiceDesk Plus <= 9.1 build 9110. The vulnerability allows arbitrary file download via the 'fName' parameter in FileDownload.jsp, with SYSTEM privileges on Windows.
Description
ManageEngine ServiceDesk Plus 9.1 build 9110 - Directory Traversal
Exploits (1)
exploitdb
WRITEUP
by xistence · textwebappsjsp
https://www.exploit-db.com/exploits/38395
This is a technical writeup detailing an unauthenticated path traversal vulnerability in ManageEngine ServiceDesk Plus <= 9.1 build 9110. The vulnerability allows arbitrary file download via the 'fName' parameter in FileDownload.jsp, with SYSTEM privileges on Windows.
Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
ManageEngine ServiceDesk Plus <= 9.1 build 9110
No auth needed
Prerequisites:
Network access to the target server
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026