EIP-2026-106459

PRE-CVE

DirectAdmin Web Control Panel 1.483 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106459. PoCs published by Ashiyane Digital Security Team.

AI-analyzed exploit summary The exploit demonstrates multiple CSRF and XSS vulnerabilities in DirectAdmin Web Control Panel, allowing unauthorized actions such as file manipulation, FTP account creation, and database creation via crafted POST requests.

Description

DirectAdmin Web Control Panel 1.483 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by Ashiyane Digital Security Team · textwebappsphp
https://www.exploit-db.com/exploits/38110

The exploit demonstrates multiple CSRF and XSS vulnerabilities in DirectAdmin Web Control Panel, allowing unauthorized actions such as file manipulation, FTP account creation, and database creation via crafted POST requests.

Classification
Working Poc 90%
Attack Type
Xss | Csrf
Complexity
Trivial
Reliability
Reliable
Target: DirectAdmin Web Control Panel (version unspecified, likely pre-2015/09/08)
No auth needed
Prerequisites: Victim must be authenticated in DirectAdmin · Attacker must lure victim to a malicious page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026