EIP-2026-118958
PRE-CVENetSuite 1.0/1.2 - HTTP Server Directory Traversal
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118958. PoCs published by dr_insane.
AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in NetSuite's HTTP component, allowing attackers to access files outside the web root using encoded traversal sequences. No actual exploit code is present, only example URLs demonstrating the vulnerability.
Description
NetSuite 1.0/1.2 - HTTP Server Directory Traversal
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by dr_insane · textremotewindows
https://www.exploit-db.com/exploits/22909
The provided text describes a directory traversal vulnerability in NetSuite's HTTP component, allowing attackers to access files outside the web root using encoded traversal sequences. No actual exploit code is present, only example URLs demonstrating the vulnerability.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:
NetSuite HTTP component
No auth needed
Prerequisites:
Network access to the target NetSuite instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026