EIP-2026-104514
PRE-CVEZenoss 3.2.1 - (Authenticated) Remote Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104514. PoCs published by Brendan Coles.
AI-analyzed exploit summary This exploit demonstrates a post-authentication remote command execution vulnerability in Zenoss <= 3.2.1. It authenticates with provided credentials, adds a malicious command to the Zenoss event manager, triggers the command to execute a reverse shell, and cleans up by removing the command and trigger.
Description
Zenoss 3.2.1 - (Authenticated) Remote Command Execution
Exploits (1)
This exploit demonstrates a post-authentication remote command execution vulnerability in Zenoss <= 3.2.1. It authenticates with provided credentials, adds a malicious command to the Zenoss event manager, triggers the command to execute a reverse shell, and cleans up by removing the command and trigger.