EIP-2026-106224

PRE-CVE

cPassMan 1.82 - Remote Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106224. PoCs published by ls.

AI-analyzed exploit summary This exploit demonstrates a two-stage attack against cPassMan v1.82: an unauthenticated arbitrary file upload followed by a local file inclusion (LFI) to achieve remote command execution (RCE). The PoC uploads a malicious PHP file and then includes it via a poison null byte in the user_language cookie.

Description

cPassMan 1.82 - Remote Command Execution

Exploits (1)

exploitdb WORKING POC
by ls · phpwebappsphp
https://www.exploit-db.com/exploits/18522

This exploit demonstrates a two-stage attack against cPassMan v1.82: an unauthenticated arbitrary file upload followed by a local file inclusion (LFI) to achieve remote command execution (RCE). The PoC uploads a malicious PHP file and then includes it via a poison null byte in the user_language cookie.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Collaborative Passwords Manager (cPassMan) v1.82
No auth needed
Prerequisites: PHP 5.3.3 or lower (due to poison null byte usage) · Network access to the target web server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026