EIP-2026-104086
PRE-CVESplunk 5.0 - Custom App Remote Code Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104086. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a feature in Splunk 5.0 where a custom application can be uploaded and executed via the 'script' search command, allowing remote code execution. It authenticates as an admin user, uploads a malicious app, and triggers payload execution.
Description
Splunk 5.0 - Custom App Remote Code Execution (Metasploit)
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/23224
This Metasploit module exploits a feature in Splunk 5.0 where a custom application can be uploaded and executed via the 'script' search command, allowing remote code execution. It authenticates as an admin user, uploads a malicious app, and triggers payload execution.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Splunk 5.0.1
Auth required
Prerequisites:
Valid admin credentials (default: admin:changeme) · Network access to Splunk web interface (port 8000)
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026