EIP-2026-104013

PRE-CVE

Nutanix AOS & Prism < 5.5.5 (LTS) / < 5.8.1 (STS) - SFTP Authentication Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104013. PoCs published by Adam Brown.

AI-analyzed exploit summary This PoC exploits an authentication bypass vulnerability in Nutanix AOS & Prism SFTP server by skipping the authentication step and directly opening an SFTP channel to list the root directory. It leverages a flaw in the SFTP server's handling of channel requests before authentication is completed.

Description

Nutanix AOS & Prism < 5.5.5 (LTS) / < 5.8.1 (STS) - SFTP Authentication Bypass

Exploits (1)

exploitdb WORKING POC
by Adam Brown · pythonremotemultiple
https://www.exploit-db.com/exploits/45748

This PoC exploits an authentication bypass vulnerability in Nutanix AOS & Prism SFTP server by skipping the authentication step and directly opening an SFTP channel to list the root directory. It leverages a flaw in the SFTP server's handling of channel requests before authentication is completed.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Nutanix AOS & Prism < 5.5.5 (LTS), < 5.8.1 (STS)
No auth needed
Prerequisites: Network access to the target SFTP server (port 2222) · Paramiko library installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026