EIP-2026-118939
PRE-CVEMySQL 4.x/5.0 (Windows) - User-Defined Function Command Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118939. PoCs published by Marco Ivaldi.
AI-analyzed exploit summary This is a MySQL UDF (User Defined Function) backdoor kit for Windows, designed to spawn a reverse shell or execute OS commands. It leverages MySQL's UDF mechanism to achieve remote code execution.
Description
MySQL 4.x/5.0 (Windows) - User-Defined Function Command Execution
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Marco Ivaldi · textremotewindows
https://www.exploit-db.com/exploits/3274
This is a MySQL UDF (User Defined Function) backdoor kit for Windows, designed to spawn a reverse shell or execute OS commands. It leverages MySQL's UDF mechanism to achieve remote code execution.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
MySQL 4.0.18-win32, 4.1.22-win32, 5.0.27-win32
Auth required
Prerequisites:
Access to MySQL server with sufficient privileges to create UDFs · MySQL server running on Windows
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026