EIP-2026-104765

PRE-CVE

Piwik 2.14.0/2.16.0/2.17.1/3.0.1 - Superuser Plugin Upload (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104765. PoCs published by Metasploit.

AI-analyzed exploit summary This Metasploit module exploits a plugin upload vulnerability in Piwik to achieve remote code execution by generating a malicious plugin, packaging it as a ZIP, and uploading it via authenticated superuser access. It targets Piwik versions 2.x and 3.x, bypassing version 1.x due to lack of plugin upload functionality.

Description

Piwik 2.14.0/2.16.0/2.17.1/3.0.1 - Superuser Plugin Upload (Metasploit)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/41358

This Metasploit module exploits a plugin upload vulnerability in Piwik to achieve remote code execution by generating a malicious plugin, packaging it as a ZIP, and uploading it via authenticated superuser access. It targets Piwik versions 2.x and 3.x, bypassing version 1.x due to lack of plugin upload functionality.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Piwik 2.14.0, 2.16.0, 2.17.1, 3.0.1
Auth required
Prerequisites: Valid superuser credentials for Piwik · Plugin upload functionality enabled (Piwik 2.x/3.x)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026