EIP-2026-116586

PRE-CVE

XAMPP - Buffer Overflow POC

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116586. PoCs published by Talson.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in XAMPP v3.3.0 via a maliciously crafted 'xampp-control.ini' file. It leverages SEH overwrite and Unicode-compatible shellcode to execute arbitrary commands (e.g., calc.exe) when the 'admin' button is clicked in the XAMPP control panel.

Description

XAMPP - Buffer Overflow POC

Exploits (1)

exploitdb WORKING POC
by Talson · pythondoswindows
https://www.exploit-db.com/exploits/51800

This exploit demonstrates a buffer overflow vulnerability in XAMPP v3.3.0 via a maliciously crafted 'xampp-control.ini' file. It leverages SEH overwrite and Unicode-compatible shellcode to execute arbitrary commands (e.g., calc.exe) when the 'admin' button is clicked in the XAMPP control panel.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: XAMPP v3.3.0
No auth needed
Prerequisites: XAMPP v3.3.0 installed on Windows · Ability to write to 'c:\xampp\xampp-control.ini'
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026