EIP-2026-118795

PRE-CVE

Microsoft IIS 6.0 - WebDAV Remote Authentication Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118795. PoCs published by racle.

AI-analyzed exploit summary This exploit targets a WebDAV vulnerability in IIS 6, allowing arbitrary file upload and remote code execution via crafted HTTP requests. It uses Unicode encoding (%c0%af) to bypass security checks and uploads a malicious file (test.txt) as an ASP script.

Description

Microsoft IIS 6.0 - WebDAV Remote Authentication Bypass

Exploits (1)

exploitdb WORKING POC VERIFIED
by racle · phpremotewindows
https://www.exploit-db.com/exploits/8765

This exploit targets a WebDAV vulnerability in IIS 6, allowing arbitrary file upload and remote code execution via crafted HTTP requests. It uses Unicode encoding (%c0%af) to bypass security checks and uploads a malicious file (test.txt) as an ASP script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft IIS 6.0
No auth needed
Prerequisites: WebDAV enabled on IIS 6 · Network access to target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026