EIP-2026-104069
PRE-CVESAP ConfigServlet - OS Command Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104069. PoCs published by Andras Kabai.
AI-analyzed exploit summary This Metasploit auxiliary module exploits an unauthenticated OS command execution vulnerability in SAP ConfigServlet by sending a crafted GET request with a command embedded in the query parameter. It checks for a successful response containing 'Process created' to confirm exploitation.
Description
SAP ConfigServlet - OS Command Execution (Metasploit)
Exploits (1)
This Metasploit auxiliary module exploits an unauthenticated OS command execution vulnerability in SAP ConfigServlet by sending a crafted GET request with a command embedded in the query parameter. It checks for a successful response containing 'Process created' to confirm exploitation.