EIP-2026-118410

PRE-CVE

Disk Pulse Enterprise 9.1.16 - 'Login' Remote Buffer Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118410. PoCs published by Tulpa.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Disk Pulse Enterprise 9.1.16, leveraging a crafted HTTP POST request to achieve remote code execution (RCE) with NT AUTHORITY\SYSTEM privileges. The payload includes shellcode generated by msfvenom and an egghunter to bypass memory constraints.

Description

Disk Pulse Enterprise 9.1.16 - 'Login' Remote Buffer Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tulpa · pythonremotewindows
https://www.exploit-db.com/exploits/40835

This exploit targets a buffer overflow vulnerability in Disk Pulse Enterprise 9.1.16, leveraging a crafted HTTP POST request to achieve remote code execution (RCE) with NT AUTHORITY\SYSTEM privileges. The payload includes shellcode generated by msfvenom and an egghunter to bypass memory constraints.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Disk Pulse Enterprise 9.1.16
No auth needed
Prerequisites: Network access to the target system · Target running Disk Pulse Enterprise 9.1.16 on Windows 7 x86
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026