EIP-2026-114622

PRE-CVE

ZeroCMS 1.0 - 'zero_transact_user.php' Handling Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114622. PoCs published by Tiago Carvalho.

AI-analyzed exploit summary This exploit targets ZeroCMS 1.0 by abusing improper parameter handling in zero_transact_user.php to escalate privileges to admin (access_level=3) via a crafted POST request. It bypasses permission checks by directly modifying the access_level parameter.

Description

ZeroCMS 1.0 - 'zero_transact_user.php' Handling Privilege Escalation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tiago Carvalho · pythonwebappsphp
https://www.exploit-db.com/exploits/33743

This exploit targets ZeroCMS 1.0 by abusing improper parameter handling in zero_transact_user.php to escalate privileges to admin (access_level=3) via a crafted POST request. It bypasses permission checks by directly modifying the access_level parameter.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ZeroCMS 1.0
Auth required
Prerequisites: Valid user account credentials · User ID of the target account
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026