EIP-2026-112471

PRE-CVE

SugarCRM 12.2.0 - Remote Code Execution (RCE)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112471. PoCs published by sw33t.0day.

AI-analyzed exploit summary This exploit targets SugarCRM 12.2.0 by uploading a malicious PHAR file disguised as a PNG image, achieving remote code execution. It leverages a file upload vulnerability in the EmailTemplates module to bypass restrictions and execute arbitrary commands.

Description

SugarCRM 12.2.0 - Remote Code Execution (RCE)

Exploits (1)

exploitdb WORKING POC
by sw33t.0day · pythonwebappsphp
https://www.exploit-db.com/exploits/51187

This exploit targets SugarCRM 12.2.0 by uploading a malicious PHAR file disguised as a PNG image, achieving remote code execution. It leverages a file upload vulnerability in the EmailTemplates module to bypass restrictions and execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SugarCRM all commercial versions up to 12.2.0
No auth needed
Prerequisites: Target URL with vulnerable SugarCRM instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026