This module exploits CVE-2026-59310, a directory traversal vulnerability in the Syslog server component of VMware vCenter Server to deploy an Core Impact OSCI agent. The module will use the vulnerability to create a log file inside the /opt/vmware/share/htdocs/configurev2/ directory and then verify the result via a HTTP GET request to the /configurev2 endpoint via the 5480 port with a random filename terminated in the "-syslog.log" string. Then, the module will try to erase the created log file by using the vulnerability again to create a cron file inside the /etc/cron.d/ directory. The cron job will autodelete itself. If the target is vulnerable, the module will deploy an Core Impact OSCI agent with capabilities to execute commands as root. Due to the way the vulnerability is exploited, no command output is possible, so Core Impact OSCI agent terminal commands will be marked as blind.
This module performs the following steps: 1. Checks whether the Drupal i18n_sso token endpoint is present. 2. Submits a random token as a negative control and verifies that it is rejected. 3. Sends unauthenticated wildcard-token requests to the Drupal i18n_sso login endpoint. 4. Repeats the wildcard request according to MAX ATTEMPTS and POLL INTERVAL until a matching active token is found. 5. Confirms the authentication bypass only when Drupal reports success and returns a valid Drupal session cookie. 6. Uses the acquired session to identify the authenticated Drupal account. 7. Stores the session cookie as an Impact identity and records CVE-2026-16639 on the target.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required.
CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without requiring authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required. Linux agent delivery uses curl because standard Joomla PHP/Apache images commonly include curl without wget. The selected Impact web server must be reachable from the target container.
This module exploits the nginx stream ssl_preread/SNI variant of CVE-2026-42533. A crafted TLS Server Name Indication triggers two-pass complex-value evaluation, allowing an unauthenticated attacker to disclose process addresses and corrupt the nginx worker heap. The module captures the leaked addresses, sprays a forged cleanup handler through the HTTP listener, and triggers the corruption through the stream listener to invoke system() in the nginx worker. It then downloads and executes a Core Impact Linux agent. The attack is layout-dependent and may interrupt the nginx worker. The deployed Core Impact agent runs with the privileges of the nginx worker account.
CVE-2026-85706 is an improper path confinement and missing authentication vulnerability in the GitLab repository commits API. A remote unauthenticated attacker can forge Workhorse body-upload metadata and make GitLab read an arbitrary local file before authentication is enforced. This module sends a crafted form to the repository commits API and extracts file content reflected by a parser error. The request does not require a GitLab account, but PROJECT ID must identify an existing project that is available to unauthenticated users. The requested file is interpreted as URL-encoded form data and its content is returned only when parsing encounters malformed percent encoding. Ampersand and semicolon characters separate parameters, while the first equals sign separates a parameter name from its value. The error response includes only the name or value being decoded when the error occurs. The module cannot select a byte offset or resume parsing, so it may disclose only part of a file or no content at all. This exploit does not install an agent.
This module exploits CVE-2026-81578, an improper access control vulnerability combined with CVE-2026-82078, an unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut NG and MF to deploy an OSCI agent. The module will use the vulnerability chain via a crafted Apache Tapestry complex-direct request to invoke privileged ConfigEditor components through the public Home page. On version 26 of the affected software, the module reconfigures external user lookup to use an H2 JDBC URL whose initialization SQL evaluates Groovy code. On versions 24 and 25, it uses a bundled Derby procedure to write a temporary Groovy bootstrap class to the application classpath and then loads it as a database driver. Due to the way the vulnerability chain is exploited, the command output cannot be reliably in-band through the existing lookup response, so OSCI agent commands will be marked as blind, meaning that no command output will be returned.
CVE-2026-9198 is an unauthenticated remote code execution vulnerability chain in Langflow OSS when AUTO_LOGIN is enabled. An unauthenticated network attacker can exploit CVE-2026-9103 to obtain a superuser access token from /api/v1/auto_login without credentials, then leverage CVE-2026-8481 in /api/v1/validate/code to execute user-controlled Python through exec(). By chaining these vulnerabilities, CVE-2026-9198 allows arbitrary command execution on the Langflow server. Langflow OSS versions 1.0.0 through 1.10.0, inclusive, are vulnerable. The vulnerability is fixed in version 1.10.1. The module performs the following steps: 1. Uses the selected web page URL to identify the Langflow scheme, host, port, and base path. 2. Requests an access token without credentials from /api/v1/auto_login. 3. Queries /api/v1/users/whoami and requires the returned user to have is_superuser set to true, confirming CVE-2026-9103. 4. Queries the superuser-protected /api/v1/users/?limit=1 endpoint and requires an HTTP 200 response as a second privilege check. 5. Submits a crafted Python function decorator to /api/v1/validate/code. The decorator executes immediately through exec(), and the module recovers command output from function.errors. 6. Executes the whoami command, recovers its output, and identifies the operating system reported by the vulnerable Langflow Python process, confirming CVE-2026-8481 and the complete CVE-2026-9198 chain. 7. When DEPLOY OSCI AGENT is enabled, the module commits a non-blind OSCI agent associated with CVE-2026-9198 that reuses the same Langflow primitive to relaunch commands later without copying an Impact executable to the target. 8. Stores the Langflow connection parameters required to request a fresh AUTO_LOGIN token whenever the OSCI agent executes a command. 9. Relaunches commands through /api/v1/validate/code and returns their standard output and exit status to the Impact console. 10. When DEPLOY NETWORK AGENT is enabled, the module stages an Impact payload from the embedded web server and launches it through the vulnerable Langflow service. 11. Waits for the native agent connection, associates a successful deployment with CVE-2026-9198, and performs the cleanup required by the selected deployment method. The executed commands and any deployed agent will run with the privileges of the Langflow service account.
CVE-2026-9198 is an unauthenticated remote code execution vulnerability chain in Langflow OSS when AUTO_LOGIN is enabled. An unauthenticated network attacker can exploit CVE-2026-9103 to obtain a superuser access token from /api/v1/auto_login without credentials, then leverage CVE-2026-8481 in /api/v1/validate/code to execute user-controlled Python through exec(). By chaining these vulnerabilities, CVE-2026-9198 allows arbitrary command execution on the Langflow server. Langflow OSS versions 1.0.0 through 1.10.0, inclusive, are vulnerable. The vulnerability is fixed in version 1.10.1. The module performs the following steps: 1. Determines whether the Langflow service uses plain HTTP or HTTPS. 2. Requests an access token without credentials from /api/v1/auto_login. 3. Queries /api/v1/users/whoami and requires the returned user to have is_superuser set to true, confirming CVE-2026-9103. 4. Queries the superuser-protected /api/v1/users/?limit=1 endpoint and requires an HTTP 200 response as a second privilege check. 5. Submits a crafted Python function decorator to /api/v1/validate/code. The decorator executes immediately through exec(), and the module recovers command output from function.errors. 6. Executes the whoami command, recovers its output, and identifies the operating system reported by the vulnerable Langflow Python process, confirming CVE-2026-8481 and the complete CVE-2026-9198 chain. 7. When DEPLOY OSCI AGENT is enabled, the module commits a non-blind OSCI agent associated with CVE-2026-9198 that reuses the same Langflow primitive to relaunch commands later without copying a Core Impact executable agent into the target. 8. Stores the Langflow connection parameters required to request a fresh AUTO_LOGIN token whenever the OSCI agent executes a command. 9. Relaunches commands through /api/v1/validate/code and returns their standard output and exit status to the Impact console. 10. When DEPLOY NETWORK AGENT is enabled, the module stages an Impact payload from the embedded web server and launches it through the vulnerable Langflow service. 11. Waits for the native agent connection, associates a successful deployment with CVE-2026-9198, and performs the cleanup required by the selected deployment method. The executed commands and any deployed agent will run with the privileges of the Langflow service account.
This module exploits CVE-2026-53365, to elevate privileges on a Linux target. The vulnerability is a page-reference-count underflow in the Linux kernel io_uring zero-copy send path over AF_VSOCK. It can free a page that remains pinned and allow the page to be reclaimed as privileged file page-cache data. The exploit uses the vulnerability to modify the interpreter path in the page-cache contents of "/usr/bin/su" and execute a caller-supplied ELF with root privileges. The module uploads the exploit binary and a generated Core Impact agent ELF with random names to the directory selected by the TMP_DIR parameter. After successful exploitation, its setuid helper executes that agent with root privileges. Before exploitation, the module refuses to continue if the cached "/usr/bin/su" image already references the exploit interpreter and removes stale files from previous failed attempts. After the privileged interpreter has executed, the exploit restores the original cached "/usr/bin/su" ELF page through its fixed-buffer alias before tearing down the io_uring worker. After the new agent connects, the module waits for a privileged filesystem-cache eviction, verifies that the cached "/usr/bin/su" image no longer references the exploit interpreter, and removes the uploaded files and fixed-name exploit artifacts. Even after successful restoration, another exploitation attempt requires a reboot because the affected page and allocator state are not reusable during the same boot.