This module performs the following steps: 1. Checks whether the Drupal i18n_sso token endpoint is present. 2. Submits a random token as a negative control and verifies that it is rejected. 3. Sends unauthenticated wildcard-token requests to the Drupal i18n_sso login endpoint. 4. Repeats the wildcard request according to MAX ATTEMPTS and POLL INTERVAL until a matching active token is found. 5. Confirms the authentication bypass only when Drupal reports success and returns a valid Drupal session cookie. 6. Uses the acquired session to identify the authenticated Drupal account. 7. Stores the session cookie as an Impact identity and records CVE-2026-16639 on the target.
A Windows Component Based Servicing elevation of privilege vulnerability allows a local attacker to make a SYSTEM TiWorker process load an unsigned sibling dpx.dll from a controlled OnePackage metadata directory. The module performs the following steps: Generates a per-run CORE Impact agent DLL named dpx.dll. Copies the target's installed, signed UpdateAgent.dll and builds a reduced DesktopDeployment cabinet with the controlled dpx.dll. Builds a small standalone OnePackage carrier on the target by using the Windows makecab utility. Executes the CBS helper directly from memory without writing the helper executable to the target filesystem. Invokes the public CBS Session COM endpoint and evaluates applicability without staging, installing, or committing the package. Causes UpdateAgent.dll to load the controlled sibling dpx.dll inside TiWorker.exe.
This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact network Agent.
This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact agent with root privileges.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without requiring authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required. Linux agent delivery uses curl because standard Joomla PHP/Apache images commonly include curl without wget. The selected Impact web server must be reachable from the target container.
This module exploits the nginx stream ssl_preread/SNI variant of CVE-2026-42533. A crafted TLS Server Name Indication triggers two-pass complex-value evaluation, allowing an unauthenticated attacker to disclose process addresses and corrupt the nginx worker heap. The module captures the leaked addresses, sprays a forged cleanup handler through the HTTP listener, and triggers the corruption through the stream listener to invoke system() in the nginx worker. It then downloads and executes a Core Impact Linux agent. The attack is layout-dependent and may interrupt the nginx worker. The deployed Core Impact agent runs with the privileges of the nginx worker account.
CVE-2026-85706 is an improper path confinement and missing authentication vulnerability in the GitLab repository commits API. A remote unauthenticated attacker can forge Workhorse body-upload metadata and make GitLab read an arbitrary local file before authentication is enforced. This module sends a crafted form to the repository commits API and extracts file content reflected by a parser error. The request does not require a GitLab account, but PROJECT ID must identify an existing project that is available to unauthenticated users. The requested file is interpreted as URL-encoded form data and its content is returned only when parsing encounters malformed percent encoding. Ampersand and semicolon characters separate parameters, while the first equals sign separates a parameter name from its value. The error response includes only the name or value being decoded when the error occurs. The module cannot select a byte offset or resume parsing, so it may disclose only part of a file or no content at all. This exploit does not install an agent.
This module exploits CVE-2026-81578, an improper access control vulnerability combined with CVE-2026-82078, an unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut NG and MF to deploy an OSCI agent. The module will use the vulnerability chain via a crafted Apache Tapestry complex-direct request to invoke privileged ConfigEditor components through the public Home page. On version 26 of the affected software, the module reconfigures external user lookup to use an H2 JDBC URL whose initialization SQL evaluates Groovy code. On versions 24 and 25, it uses a bundled Derby procedure to write a temporary Groovy bootstrap class to the application classpath and then loads it as a database driver. Due to the way the vulnerability chain is exploited, the command output cannot be reliably in-band through the existing lookup response, so OSCI agent commands will be marked as blind, meaning that no command output will be returned.
CVE-2026-9198 is an unauthenticated remote code execution vulnerability chain in Langflow OSS when AUTO_LOGIN is enabled. An unauthenticated network attacker can exploit CVE-2026-9103 to obtain a superuser access token from /api/v1/auto_login without credentials, then leverage CVE-2026-8481 in /api/v1/validate/code to execute user-controlled Python through exec(). By chaining these vulnerabilities, CVE-2026-9198 allows arbitrary command execution on the Langflow server. Langflow OSS versions 1.0.0 through 1.10.0, inclusive, are vulnerable. The vulnerability is fixed in version 1.10.1. The module performs the following steps: 1. Uses the selected web page URL to identify the Langflow scheme, host, port, and base path. 2. Requests an access token without credentials from /api/v1/auto_login. 3. Queries /api/v1/users/whoami and requires the returned user to have is_superuser set to true, confirming CVE-2026-9103. 4. Queries the superuser-protected /api/v1/users/?limit=1 endpoint and requires an HTTP 200 response as a second privilege check. 5. Submits a crafted Python function decorator to /api/v1/validate/code. The decorator executes immediately through exec(), and the module recovers command output from function.errors. 6. Executes the whoami command, recovers its output, and identifies the operating system reported by the vulnerable Langflow Python process, confirming CVE-2026-8481 and the complete CVE-2026-9198 chain. 7. When DEPLOY OSCI AGENT is enabled, the module commits a non-blind OSCI agent associated with CVE-2026-9198 that reuses the same Langflow primitive to relaunch commands later without copying an Impact executable to the target. 8. Stores the Langflow connection parameters required to request a fresh AUTO_LOGIN token whenever the OSCI agent executes a command. 9. Relaunches commands through /api/v1/validate/code and returns their standard output and exit status to the Impact console. 10. When DEPLOY NETWORK AGENT is enabled, the module stages an Impact payload from the embedded web server and launches it through the vulnerable Langflow service. 11. Waits for the native agent connection, associates a successful deployment with CVE-2026-9198, and performs the cleanup required by the selected deployment method. The executed commands and any deployed agent will run with the privileges of the Langflow service account.