EIP-2026-110268

PRE-CVE

OpenCart 2.1.0.2 < 2.2.0.0 - json_decode Function Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110268. PoCs published by Naser Farhadi.

AI-analyzed exploit summary This exploit leverages a vulnerability in OpenCart's json_decode function in /upload/system/helper/json.php, where improper sanitization allows PHP code injection. The exploit demonstrates RCE by injecting malicious payloads into user-controlled fields, which are executed when processed by the vulnerable function.

Description

OpenCart 2.1.0.2 < 2.2.0.0 - json_decode Function Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by Naser Farhadi · textwebappsphp
https://www.exploit-db.com/exploits/39679

This exploit leverages a vulnerability in OpenCart's json_decode function in /upload/system/helper/json.php, where improper sanitization allows PHP code injection. The exploit demonstrates RCE by injecting malicious payloads into user-controlled fields, which are executed when processed by the vulnerable function.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenCart 2.1.0.2 to 2.2.0.0
Auth required
Prerequisites: PHP JSON extension not installed · Access to user input fields (e.g., account/edit, custom_field) · Admin interaction for some scenarios
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026