EIP-2026-111690

PRE-CVE

rConfig 3.1.1 - Local File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111690. PoCs published by Gregory Pickett.

AI-analyzed exploit summary The writeup describes a local file inclusion vulnerability in rConfig's downloadFile.php, allowing authenticated users to download arbitrary files from the server. The vulnerability is due to lack of validation on the download_file parameter.

Description

rConfig 3.1.1 - Local File Inclusion

Exploits (1)

exploitdb WRITEUP
by Gregory Pickett · textwebappsphp
https://www.exploit-db.com/exploits/39898

The writeup describes a local file inclusion vulnerability in rConfig's downloadFile.php, allowing authenticated users to download arbitrary files from the server. The vulnerability is due to lack of validation on the download_file parameter.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: rConfig 3.1.1 and earlier
Auth required
Prerequisites: Authenticated access to the rConfig application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026