EIP-2026-118707

PRE-CVE

Jira Scriptrunner 2.0.7 - Cross-Site Request Forgery / Remote Code Execution (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118707. PoCs published by Ben Sheppard.

AI-analyzed exploit summary This Metasploit module exploits a CSRF vulnerability in Jira Scriptrunner 2.0.7 to achieve remote code execution (RCE) by submitting a crafted Groovy script via a hidden HTML form. The exploit generates a base64-encoded payload, writes it to an executable file, and executes it on the target system.

Description

Jira Scriptrunner 2.0.7 - Cross-Site Request Forgery / Remote Code Execution (Metasploit)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ben Sheppard · rubyremotewindows
https://www.exploit-db.com/exploits/22678

This Metasploit module exploits a CSRF vulnerability in Jira Scriptrunner 2.0.7 to achieve remote code execution (RCE) by submitting a crafted Groovy script via a hidden HTML form. The exploit generates a base64-encoded payload, writes it to an executable file, and executes it on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Jira Scriptrunner 2.0.7
No auth needed
Prerequisites: Target must have Jira Scriptrunner 2.0.7 installed · Target must be accessible via HTTP/HTTPS
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026