EIP-2026-106485

PRE-CVE

Docebo 3.6.0.2 (stable) - Local File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106485. PoCs published by Zer0 Thunder.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Docebo 3.6.0.2 by manipulating the 'modname' parameter in the URL to include arbitrary files, such as 'boot.ini', via directory traversal sequences. The PoC is tested on a specific environment (WampServer 2.0i) and provides a clear example of the vulnerability.

Description

Docebo 3.6.0.2 (stable) - Local File Inclusion

Exploits (1)

exploitdb WORKING POC VERIFIED
by Zer0 Thunder · textwebappsphp
https://www.exploit-db.com/exploits/11028

This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Docebo 3.6.0.2 by manipulating the 'modname' parameter in the URL to include arbitrary files, such as 'boot.ini', via directory traversal sequences. The PoC is tested on a specific environment (WampServer 2.0i) and provides a clear example of the vulnerability.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Docebo 3.6.0.2
No auth needed
Prerequisites: Access to the target web application · Knowledge of the file path to be included
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026