EIP-2026-104341

PRE-CVE

Mobile Atlas Creator 1.9.12 - Persistent Command Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104341. PoCs published by Vulnerability-Lab.

AI-analyzed exploit summary The document describes a persistent command injection vulnerability in Mobile Atlas Creator 1.9.12, where improper input sanitization in the 'Name' field allows HTML and local command path injection. The vulnerability can be exploited by saving malicious script code as an Atlas Map file and sending it to victims.

Description

Mobile Atlas Creator 1.9.12 - Persistent Command Injection

Exploits (1)

exploitdb WRITEUP
by Vulnerability-Lab · textwebappsmultiple
https://www.exploit-db.com/exploits/26621

The document describes a persistent command injection vulnerability in Mobile Atlas Creator 1.9.12, where improper input sanitization in the 'Name' field allows HTML and local command path injection. The vulnerability can be exploited by saving malicious script code as an Atlas Map file and sending it to victims.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Mobile Atlas Creator 1.9.12
No auth needed
Prerequisites: Local access to the application · Ability to create a new Atlas Map
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026