This module exploits CVE-2026-88771, a command injection vulnerability present in the ns_monuploadd_err.pl script of Citrix NetScaler ADC and Gateway to deploy a Core Impact Network agent that will run with root privileges. The module will exploit the vulnerability by sending a crafted HTTP POST request the /p/u/doAuthentication.do endpoint with the payload inside the User-Agent header. The result of the HTTP request will determine if the command injection was successful. If the command injection is successful, the module will wait up to 24 hours for agent connection. This is because the appliance runs the ns_monuploadd_err.pl script every 24 hours and the attack has no way to determine the current timelapse for this behaviour. The deployed Core Impact Network agent will run with root privileges.
This module exploits CVE-2026-59310, a directory traversal vulnerability in the Syslog server component of VMware vCenter Server to deploy an Core Impact OSCI agent. The module will use the vulnerability to create a log file inside the /opt/vmware/share/htdocs/configurev2/ directory and then verify the result via a HTTP GET request to the /configurev2 endpoint via the 5480 port with a random filename terminated in the "-syslog.log" string. Then, the module will try to erase the created log file by using the vulnerability again to create a cron file inside the /etc/cron.d/ directory. The cron job will autodelete itself. If the target is vulnerable, the module will deploy an Core Impact OSCI agent with capabilities to execute commands as root. Due to the way the vulnerability is exploited, no command output is possible, so Core Impact OSCI agent terminal commands will be marked as blind.
This module performs the following steps: 1. Checks whether the Drupal i18n_sso token endpoint is present. 2. Submits a random token as a negative control and verifies that it is rejected. 3. Sends unauthenticated wildcard-token requests to the Drupal i18n_sso login endpoint. 4. Repeats the wildcard request according to MAX ATTEMPTS and POLL INTERVAL until a matching active token is found. 5. Confirms the authentication bypass only when Drupal reports success and returns a valid Drupal session cookie. 6. Uses the acquired session to identify the authenticated Drupal account. 7. Stores the session cookie as an Impact identity and records CVE-2026-16639 on the target.
This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact network Agent.
This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact agent with root privileges.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without requiring authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required. Linux agent delivery uses curl because standard Joomla PHP/Apache images commonly include curl without wget. The selected Impact web server must be reachable from the target container.
This module exploits CVE-2026-81578, an improper access control vulnerability combined with CVE-2026-82078, an unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut NG and MF to deploy an OSCI agent. The module will use the vulnerability chain via a crafted Apache Tapestry complex-direct request to invoke privileged ConfigEditor components through the public Home page. On version 26 of the affected software, the module reconfigures external user lookup to use an H2 JDBC URL whose initialization SQL evaluates Groovy code. On versions 24 and 25, it uses a bundled Derby procedure to write a temporary Groovy bootstrap class to the application classpath and then loads it as a database driver. Due to the way the vulnerability chain is exploited, the command output cannot be reliably in-band through the existing lookup response, so OSCI agent commands will be marked as blind, meaning that no command output will be returned.
ResetNightmare is an authorization flaw in the Microsoft Kerberos Change Password protocol. On an unpatched domain controller, an attacker who can write the userPrincipalName attribute of a controlled account can obtain a kadmin/changepw ticket whose client name identifies another account while its PAC identifies the controlled account. The module temporarily changes the controlled account's UPN to the target sAMAccountName, requests a kadmin/changepw ticket with an NT-ENTERPRISE client name, restores the original UPN, and uses the ticket in an RFC 3244 password-change exchange. The target credentials are verified and stored as an Impact identity by default. The controlled account can be an existing user or computer whose cleartext password is known and whose userPrincipalName can be modified.
This module exploits CVE-2026-63077, a pre-authentication unsafe XML deserialization vulnerability in JetBrains TeamCity On-Premises. It registers a synthetic build agent through the agent polling protocol and submits a crafted XML document using the resulting agent session, without requiring TeamCity user credentials. Deserialization of the payload initializes an in-memory HSQLDB data source and uses HSQLDB's SCRIPT functionality to write a temporary JSP payload into the TeamCity ROOT web application. The module requests this JSP to execute an operating-system command as the account running the TeamCity server service. The JSP captures combined standard output and standard error, deletes itself when invoked, and is guarded against repeated execution. The module can verify the vulnerability, identify Linux or Windows targets, execute commands, and deploy an encrypted OSCI agent. It supports HTTP and HTTPS targets, including IPv6 addresses. Agent deployment is implemented for x86-64 Linux and Windows systems. Each command requires three HTTP requests: synthetic-agent registration, delivery of the deserialization payload, and invocation of the generated JSP. Commands are limited to 2026 characters, execution is limited to approximately 10 seconds, and captured output is limited to 1 MiB. Commands are executed with the privileges of the TeamCity server process. The exploit was tested against TeamCity 2025.11.6 on Ubuntu Linux 26.04 LTS and Windows Server 2025 Datacenter. Other vulnerable versions or platforms may also be affected but have not been verified by the engineering team.