EIP-2026-104324
PRE-CVEManageEngine Network Configuration Management Build 11000 - Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104324. PoCs published by Kaustubh G. Padwad.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in ManageEngine Network Configuration Manager by allowing an operator-level user to change the admin password via an API call with insufficient authentication checks.
Description
ManageEngine Network Configuration Management Build 11000 - Privilege Escalation
Exploits (1)
exploitdb
WORKING POC
by Kaustubh G. Padwad · textwebappsmultiple
https://www.exploit-db.com/exploits/39450
This exploit demonstrates a privilege escalation vulnerability in ManageEngine Network Configuration Manager by allowing an operator-level user to change the admin password via an API call with insufficient authentication checks.
Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
ManageEngine Network Configuration Manager Build 11000
Auth required
Prerequisites:
Operator account credentials · API key from operator session
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026