EIP-2026-118958

PRE-CVE

NetSuite 1.0/1.2 - HTTP Server Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118958. PoCs published by dr_insane.

AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in NetSuite's HTTP component, allowing attackers to access files outside the web root using encoded traversal sequences. No actual exploit code is present, only example URLs demonstrating the vulnerability.

Description

NetSuite 1.0/1.2 - HTTP Server Directory Traversal

Exploits (1)

exploitdb WRITEUP VERIFIED
by dr_insane · textremotewindows
https://www.exploit-db.com/exploits/22909

The provided text describes a directory traversal vulnerability in NetSuite's HTTP component, allowing attackers to access files outside the web root using encoded traversal sequences. No actual exploit code is present, only example URLs demonstrating the vulnerability.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: NetSuite HTTP component
No auth needed
Prerequisites: Network access to the target NetSuite instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026