EIP-2026-106207

PRE-CVE

cPanel 10.8.1/10.8.2 - OnMouseover Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106207. PoCs published by MexHackTeam.org.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in cPanel by injecting malicious JavaScript into the 'file' parameter of the 'select.html' page. The payload executes arbitrary script code in the context of the affected site, potentially stealing cookie-based authentication credentials.

Description

cPanel 10.8.1/10.8.2 - OnMouseover Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by MexHackTeam.org · textwebappsphp
https://www.exploit-db.com/exploits/28113

This exploit demonstrates a cross-site scripting (XSS) vulnerability in cPanel by injecting malicious JavaScript into the 'file' parameter of the 'select.html' page. The payload executes arbitrary script code in the context of the affected site, potentially stealing cookie-based authentication credentials.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: cPanel (version not specified)
No auth needed
Prerequisites: Access to a vulnerable cPanel instance · Victim interaction (e.g., hovering over the malicious link)
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026