EIP-2026-119265
PRE-CVEWebCatalog 48.4 - Arbitrary Protocol Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119265. PoCs published by ItsSixtyN3in.
AI-analyzed exploit summary This exploit leverages WebCatalog's improper handling of arbitrary protocols via Electron's shell.openExternal function. By crafting a malicious 'search-ms://' URL, an attacker can trigger execution of a reverse shell payload hosted on an SMB share when the victim interacts with the link.
Description
WebCatalog 48.4 - Arbitrary Protocol Execution
Exploits (1)
This exploit leverages WebCatalog's improper handling of arbitrary protocols via Electron's shell.openExternal function. By crafting a malicious 'search-ms://' URL, an attacker can trigger execution of a reverse shell payload hosted on an SMB share when the victim interacts with the link.