VMware vCenter Server Syslog Directory Traversal Remote Code Execution Vulnerability Exploit

This module exploits CVE-2026-59310, a directory traversal vulnerability in the Syslog server component of VMware vCenter Server to deploy an Core Impact OSCI agent. The module will use the vulnerability to create a log file inside the /opt/vmware/share/htdocs/configurev2/ directory and then verify the result via a HTTP GET request to the /configurev2 endpoint via the 5480 port with a random filename terminated in the "-syslog.log" string. Then, the module will try to erase the created log file by using the vulnerability again to create a cron file inside the /etc/cron.d/ directory. The cron job will autodelete itself. If the target is vulnerable, the module will deploy an Core Impact OSCI agent with capabilities to execute commands as root. Due to the way the vulnerability is exploited, no command output is possible, so Core Impact OSCI agent terminal commands will be marked as blind.
Exploit Platform
Product Name