EIP-2026-104642

PRE-CVE

OSSEC WUI 0.8 - Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104642. PoCs published by Milad Saber.

AI-analyzed exploit summary This exploit targets OSSEC WUI 0.8 by leveraging a directory traversal vulnerability to create a malicious user and inject a payload via SMTP. The payload executes arbitrary commands when a user logs in, demonstrating a denial-of-service (DoS) or potential remote code execution (RCE) scenario.

Description

OSSEC WUI 0.8 - Denial of Service

Exploits (1)

exploitdb WORKING POC
by Milad Saber · pythondosphp
https://www.exploit-db.com/exploits/37728

This exploit targets OSSEC WUI 0.8 by leveraging a directory traversal vulnerability to create a malicious user and inject a payload via SMTP. The payload executes arbitrary commands when a user logs in, demonstrating a denial-of-service (DoS) or potential remote code execution (RCE) scenario.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OSSEC WUI 0.8
Auth required
Prerequisites: OSSEC WUI 0.8 installed · Network access to the target server · Valid credentials for authentication
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026