EIP-2026-117897

PRE-CVE

SAPSprint 7.60 - 'SAPSprint' Unquoted Service Path

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117897. PoCs published by Brian Rodriguez.

AI-analyzed exploit summary This is a writeup detailing the discovery of an unquoted service path vulnerability in SAPSprint 7.60. The vulnerability allows for potential privilege escalation due to the service path containing spaces and lacking quotes, which could be exploited by placing a malicious executable in the path.

Description

SAPSprint 7.60 - 'SAPSprint' Unquoted Service Path

Exploits (1)

exploitdb WRITEUP
by Brian Rodriguez · textlocalwindows
https://www.exploit-db.com/exploits/50061

This is a writeup detailing the discovery of an unquoted service path vulnerability in SAPSprint 7.60. The vulnerability allows for potential privilege escalation due to the service path containing spaces and lacking quotes, which could be exploited by placing a malicious executable in the path.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Theoretical
Target: SAPSprint 7.60
Auth required
Prerequisites: Local access to the system · Ability to write to the directory structure where the unquoted service path is located
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026