EIP-2026-103523

PRE-CVE

Java - Trigerring Java Code from a .SVG Image

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103523. PoCs published by Nicolas Gregoire.

AI-analyzed exploit summary The exploit leverages SVG's ability to execute Java code when opened, using a malicious SVG file and a JAR payload to achieve remote code execution. The PoC files are hosted externally but are directly linked in the ExploitDB entry.

Description

Java - Trigerring Java Code from a .SVG Image

Exploits (1)

exploitdb WORKING POC
by Nicolas Gregoire · textdosmultiple
https://www.exploit-db.com/exploits/18890

The exploit leverages SVG's ability to execute Java code when opened, using a malicious SVG file and a JAR payload to achieve remote code execution. The PoC files are hosted externally but are directly linked in the ExploitDB entry.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache Batik (SVG processing library)
No auth needed
Prerequisites: Victim must open the malicious SVG file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026