EIP-2026-103052

PRE-CVE

Zblast 1.2 - 'Username' Local Buffer Overrun

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103052. PoCs published by V9.

AI-analyzed exploit summary This exploit targets a local buffer overflow in zblast/xzb v1.2 by overflowing the ZBLAST_NAME environment variable to execute arbitrary shellcode, granting the attacker the 'games' group privileges. The exploit uses a standard stack-based overflow technique with NOP sleds and a hardcoded return address.

Description

Zblast 1.2 - 'Username' Local Buffer Overrun

Exploits (1)

exploitdb WORKING POC VERIFIED
by V9 · clocallinux
https://www.exploit-db.com/exploits/22745

This exploit targets a local buffer overflow in zblast/xzb v1.2 by overflowing the ZBLAST_NAME environment variable to execute arbitrary shellcode, granting the attacker the 'games' group privileges. The exploit uses a standard stack-based overflow technique with NOP sleds and a hardcoded return address.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: zblast/xzb v1.2
No auth needed
Prerequisites: Local access to the system · zblast/xzb v1.2 installed with setgid games · Ability to set environment variables
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026