EIP-2026-118795
PRE-CVEMicrosoft IIS 6.0 - WebDAV Remote Authentication Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118795. PoCs published by racle.
AI-analyzed exploit summary This exploit targets a WebDAV vulnerability in IIS 6, allowing arbitrary file upload and remote code execution via crafted HTTP requests. It uses Unicode encoding (%c0%af) to bypass security checks and uploads a malicious file (test.txt) as an ASP script.
Description
Microsoft IIS 6.0 - WebDAV Remote Authentication Bypass
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by racle · phpremotewindows
https://www.exploit-db.com/exploits/8765
This exploit targets a WebDAV vulnerability in IIS 6, allowing arbitrary file upload and remote code execution via crafted HTTP requests. It uses Unicode encoding (%c0%af) to bypass security checks and uploads a malicious file (test.txt) as an ASP script.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Microsoft IIS 6.0
No auth needed
Prerequisites:
WebDAV enabled on IIS 6 · Network access to target server
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026