EIP-2026-110306

PRE-CVE

OpenFiler 2.3 - (Authentication Bypass) Remote Password Change

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110306. PoCs published by nonroot.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in OpenFiler 2.3 by manipulating password change parameters without requiring the current password. It allows a non-root user to reset the 'openfiler' admin password to an arbitrary value.

Description

OpenFiler 2.3 - (Authentication Bypass) Remote Password Change

Exploits (1)

exploitdb WORKING POC VERIFIED
by nonroot · pythonwebappsphp
https://www.exploit-db.com/exploits/7972

This exploit demonstrates an authentication bypass vulnerability in OpenFiler 2.3 by manipulating password change parameters without requiring the current password. It allows a non-root user to reset the 'openfiler' admin password to an arbitrary value.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: OpenFiler 2.3
No auth needed
Prerequisites: Network access to the OpenFiler web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026