EIP-2026-118987
PRE-CVEOpenText FirstClass Client 11.005 - Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118987. PoCs published by Kyle Ossinger.
AI-analyzed exploit summary This exploit leverages an implementation flaw in OpenText FirstClass Client to create a malicious HTA file via a crafted URI, which executes upon system reboot. The attack abuses the client's settings file mechanism to inject and execute arbitrary code.
Description
OpenText FirstClass Client 11.005 - Code Execution
Exploits (1)
exploitdb
WORKING POC
by Kyle Ossinger · textremotewindows
https://www.exploit-db.com/exploits/17156
This exploit leverages an implementation flaw in OpenText FirstClass Client to create a malicious HTA file via a crafted URI, which executes upon system reboot. The attack abuses the client's settings file mechanism to inject and execute arbitrary code.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
OpenText FirstClass Client v.11 and lower
No auth needed
Prerequisites:
Victim must click on a crafted link in the FirstClass mail client · Attacker must host a malicious JavaScript file
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026