EIP-2026-106457

PRE-CVE

DirectAdmin 1.34.4 - Multiple Cross-Site Request Forgerys

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106457. PoCs published by K053.

AI-analyzed exploit summary This exploit demonstrates multiple CSRF vulnerabilities in DirectAdmin 1.34.4, allowing unauthorized actions such as adding/deleting subdomains, emails, and databases via crafted HTML forms or image tags. The PoC includes clear examples of malicious requests that can be triggered without user interaction.

Description

DirectAdmin 1.34.4 - Multiple Cross-Site Request Forgerys

Exploits (1)

exploitdb WORKING POC
by K053 · textwebappsphp
https://www.exploit-db.com/exploits/11813

This exploit demonstrates multiple CSRF vulnerabilities in DirectAdmin 1.34.4, allowing unauthorized actions such as adding/deleting subdomains, emails, and databases via crafted HTML forms or image tags. The PoC includes clear examples of malicious requests that can be triggered without user interaction.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: DirectAdmin 1.34.4
No auth needed
Prerequisites: Victim must visit a malicious page while authenticated to DirectAdmin
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026