EIP-2026-103900

PRE-CVE

Erlang Cookie - Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103900. PoCs published by 1F98D.

AI-analyzed exploit summary This exploit leverages Erlang's distributed node authentication mechanism to execute arbitrary commands on a remote Erlang node. It authenticates using a shared cookie and sends a crafted payload to trigger remote code execution via the 'os:cmd/1' function.

Description

Erlang Cookie - Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by 1F98D · pythonremotemultiple
https://www.exploit-db.com/exploits/49418

This exploit leverages Erlang's distributed node authentication mechanism to execute arbitrary commands on a remote Erlang node. It authenticates using a shared cookie and sends a crafted payload to trigger remote code execution via the 'os:cmd/1' function.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Erlang (distributed node communication)
Auth required
Prerequisites: knowledge of the target's Erlang cookie · network access to the Erlang distribution port (default: 25672)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026