EIP-2026-106696

PRE-CVE

Easy Hosting Control Panel - Admin Authentication Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106696. PoCs published by Jasman.

AI-analyzed exploit summary This exploit describes an authentication bypass vulnerability in Easy Hosting Control Panel (EHCP) versions 0.29.10 to 0.29.13, allowing unauthenticated users to add FTP accounts and domains via specific URLs. The writeup includes steps to upload a shell via FTP but lacks actual exploit code.

Description

Easy Hosting Control Panel - Admin Authentication Bypass

Exploits (1)

exploitdb WRITEUP
by Jasman · textwebappsphp
https://www.exploit-db.com/exploits/17926

This exploit describes an authentication bypass vulnerability in Easy Hosting Control Panel (EHCP) versions 0.29.10 to 0.29.13, allowing unauthenticated users to add FTP accounts and domains via specific URLs. The writeup includes steps to upload a shell via FTP but lacks actual exploit code.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Easy Hosting Control Panel (EHCP) 0.29.10 - 0.29.13
No auth needed
Prerequisites: Access to the target EHCP instance · FTP access to upload a shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026