EIP-2026-104196
PRE-CVEchangedetection < 0.45.20 - Remote Code Execution (RCE)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104196. PoCs published by Zach Crosman (zcrosman).
AI-analyzed exploit summary This exploit leverages a Server-Side Template Injection (SSTI) vulnerability in changedetection.io <= 0.45.20 to achieve Remote Code Execution (RCE). It uses a multi-step process involving CSRF token extraction, form submission, and payload injection in the notification configuration to execute a reverse shell.
Description
changedetection < 0.45.20 - Remote Code Execution (RCE)
Exploits (1)
This exploit leverages a Server-Side Template Injection (SSTI) vulnerability in changedetection.io <= 0.45.20 to achieve Remote Code Execution (RCE). It uses a multi-step process involving CSRF token extraction, form submission, and payload injection in the notification configuration to execute a reverse shell.