EIP-2026-104013
PRE-CVENutanix AOS & Prism < 5.5.5 (LTS) / < 5.8.1 (STS) - SFTP Authentication Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104013. PoCs published by Adam Brown.
AI-analyzed exploit summary This PoC exploits an authentication bypass vulnerability in Nutanix AOS & Prism SFTP server by skipping the authentication step and directly opening an SFTP channel to list the root directory. It leverages a flaw in the SFTP server's handling of channel requests before authentication is completed.
Description
Nutanix AOS & Prism < 5.5.5 (LTS) / < 5.8.1 (STS) - SFTP Authentication Bypass
Exploits (1)
This PoC exploits an authentication bypass vulnerability in Nutanix AOS & Prism SFTP server by skipping the authentication step and directly opening an SFTP channel to list the root directory. It leverages a flaw in the SFTP server's handling of channel requests before authentication is completed.