EIP-2026-116937

PRE-CVE

CAM UnZip 5.1 - .'ZIP' File Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116937. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in CAM UnZip v5.1, allowing an attacker to write arbitrary files outside the intended extraction directory. The provided PHP script creates a malicious ZIP archive containing a file with a traversal path, which, when extracted, places a PHP file in the root directory of the system.

Description

CAM UnZip 5.1 - .'ZIP' File Directory Traversal

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · textlocalwindows
https://www.exploit-db.com/exploits/39680

This exploit demonstrates a path traversal vulnerability in CAM UnZip v5.1, allowing an attacker to write arbitrary files outside the intended extraction directory. The provided PHP script creates a malicious ZIP archive containing a file with a traversal path, which, when extracted, places a PHP file in the root directory of the system.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: CAM UnZip v5.1
No auth needed
Prerequisites: Ability to deliver a malicious ZIP archive to the target system · Target system must use CAM UnZip v5.1 to extract the archive
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026