EIP-2026-115126

PRE-CVE

Cyme ChartFX Client Server - ActiveX Control Array Indexing

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115126. PoCs published by Francis Provencher.

AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in the ChartFX ActiveX Control within CYME Power Engineering Software. It leverages an indexing error in the ShowPropertiesDialog method to write a single byte to an arbitrary memory location, potentially leading to arbitrary code execution.

Description

Cyme ChartFX Client Server - ActiveX Control Array Indexing

Exploits (1)

exploitdb WORKING POC VERIFIED
by Francis Provencher · textdoswindows
https://www.exploit-db.com/exploits/21737

This exploit targets a memory corruption vulnerability in the ChartFX ActiveX Control within CYME Power Engineering Software. It leverages an indexing error in the ShowPropertiesDialog method to write a single byte to an arbitrary memory location, potentially leading to arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CYME Power Engineering Software version 5.0.12.663
No auth needed
Prerequisites: Victim must have CYME Power Engineering Software installed · ActiveX controls must be enabled in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026