EIP-2026-118759

PRE-CVE

ManageEngine Security Manager Plus 5.5 build 5505 - Remote SYSTEM SQL Injection (Metasploit)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118759. PoCs published by xistence.

AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability in ManageEngine Security Manager Plus to achieve remote code execution by uploading a malicious JSP file and executing it. The exploit leverages a union-based SQL injection to write a JSP payload to the web root, which then downloads and executes a malicious executable.

Description

ManageEngine Security Manager Plus 5.5 build 5505 - Remote SYSTEM SQL Injection (Metasploit)

Exploits (1)

exploitdb WORKING POC VERIFIED
by xistence · rubyremotewindows
https://www.exploit-db.com/exploits/22094

This Metasploit module exploits a SQL injection vulnerability in ManageEngine Security Manager Plus to achieve remote code execution by uploading a malicious JSP file and executing it. The exploit leverages a union-based SQL injection to write a JSP payload to the web root, which then downloads and executes a malicious executable.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Security Manager Plus <=5.5 build 5505
No auth needed
Prerequisites: Network access to the target's port 6262 · Target must be running a vulnerable version of ManageEngine Security Manager Plus
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026