EIP-2026-108598

PRE-CVE

Joomla! Component com_xcloner-backupandrestore - Remote Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108598. PoCs published by mr_me.

AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in the Joomla component com_xcloner-backupandrestore. It leverages improper input validation in the XCloner.php script to overwrite the configuration.php file with malicious code via the 'output_url_pref' parameter.

Description

Joomla! Component com_xcloner-backupandrestore - Remote Command Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by mr_me · pythonwebappsphp
https://www.exploit-db.com/exploits/16246

This exploit targets a remote code execution vulnerability in the Joomla component com_xcloner-backupandrestore. It leverages improper input validation in the XCloner.php script to overwrite the configuration.php file with malicious code via the 'output_url_pref' parameter.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Joomla com_xcloner-backupandrestore (version not specified)
No auth needed
Prerequisites: Joomla with com_xcloner-backupandrestore component installed · XCloner.php script accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026