<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pre-Auth — PoC Archive</title><link>https://poc.intelseclab.com/tags/pre-auth/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/pre-auth/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-54322. Status: Weaponized. Affects: XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment). Tags: xspeeder, sxzos, sd-wan, router, firmware, python, django, eval-injection, pre-auth, rce, cwe-95.</description><category>network</category><category>Critical</category><category>xspeeder</category><category>sxzos</category><category>sd-wan</category><category>router</category><category>firmware</category><category>python</category><category>django</category><category>eval-injection</category><category>pre-auth</category><category>rce</category><category>cwe-95</category></item><item><title>SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-52691-smartermail-auth-bypass-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-52691-smartermail-auth-bypass-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-52691. Status: Weaponized. Affects: SmarterMail (SmarterTools webmail/mail server). Tags: smartermail, smartertools, webmail, authentication-bypass, password-reset, rce, volume-mounts, pre-auth, watchtowr, python.</description><category>web</category><category>Critical</category><category>smartermail</category><category>smartertools</category><category>webmail</category><category>authentication-bypass</category><category>password-reset</category><category>rce</category><category>volume-mounts</category><category>pre-auth</category><category>watchtowr</category><category>python</category></item><item><title>Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-34299. Status: Weaponized. Affects: Monsta FTP (web-based FTP manager). Tags: monsta-ftp, rce, pre-auth, unrestricted-file-upload, cwe-434, php, ftp, docker, nuclei, kev.</description><category>network</category><category>Critical</category><category>monsta-ftp</category><category>rce</category><category>pre-auth</category><category>unrestricted-file-upload</category><category>cwe-434</category><category>php</category><category>ftp</category><category>docker</category><category>nuclei</category><category>kev</category></item><item><title>Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27966-langflow-mass-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27966-langflow-mass-scanner/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-27966 (GHSA-3645-fxcv-hqr4). Status: Patched. Affects: Langflow (langflow-ai). Tags: langflow, rce, pre-auth, route-injection, vertex-injection, csv-agent, prompt-injection, python, mass-scanner, ai-security.</description><category>web</category><category>Critical</category><category>langflow</category><category>rce</category><category>pre-auth</category><category>route-injection</category><category>vertex-injection</category><category>csv-agent</category><category>prompt-injection</category><category>python</category><category>mass-scanner</category><category>ai-security</category></item><item><title>strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-35333-strongswan-radius-infinite-loop-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-35333-strongswan-radius-infinite-loop-dos/</guid><description>Medium severity — network · CVE-2026-35333. Status: PoC. Affects: strongSwan — libradius. Tags: strongswan, radius, dos, infinite-loop, integer-underflow, pre-auth.</description><category>network</category><category>Medium</category><category>strongswan</category><category>radius</category><category>dos</category><category>infinite-loop</category><category>integer-underflow</category><category>pre-auth</category></item><item><title>OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33439-openam-deserialization-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33439-openam-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-33439. Status: Weaponized. Affects: ForgeRock / OpenIdentityPlatform OpenAM. Tags: openam, forgerock, deserialization, rce, pre-auth, java, gadget-chain, xalan, jato.</description><category>web</category><category>Critical</category><category>openam</category><category>forgerock</category><category>deserialization</category><category>rce</category><category>pre-auth</category><category>java</category><category>gadget-chain</category><category>xalan</category><category>jato</category></item><item><title>NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24207-triton-sagemaker-auth-bypass-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24207-triton-sagemaker-auth-bypass-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only). Status: Weaponized. Affects: NVIDIA Triton Inference Server. Tags: nvidia-triton, sagemaker, auth-bypass, rce, cwe-288, ml-inference, model-loading, pre-auth.</description><category>network</category><category>Critical</category><category>nvidia-triton</category><category>sagemaker</category><category>auth-bypass</category><category>rce</category><category>cwe-288</category><category>ml-inference</category><category>model-loading</category><category>pre-auth</category></item><item><title>MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</guid><description>Critical severity — binary · CVE-2026-1668. Status: Weaponized. Affects: MIPS-based managed switch firmware (web management HTTP server), e.g. SG2005P/SG2008/SG2016P/SG2210MP/SG2218/SG2428/SG3210/SL2428/TL-SG2428 series firmware built around 2025-10-31. Tags: mips, embedded-linux, kernel-exploit, firmware, managed-switch, reverse-shell, pre-auth, shellcode.</description><category>binary</category><category>Critical</category><category>mips</category><category>embedded-linux</category><category>kernel-exploit</category><category>firmware</category><category>managed-switch</category><category>reverse-shell</category><category>pre-auth</category><category>shellcode</category></item><item><title>GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-32746-telnetd-linemode-slc-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-32746-telnetd-linemode-slc-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-32746. Status: PoC (overflow trigger + verification only; no code execution/shellcode included). Affects: GNU InetUtils telnetd. Tags: telnetd, inetutils, linemode, slc, buffer-overflow, pre-auth, cwe-120, cwe-787.</description><category>network</category><category>Critical</category><category>telnetd</category><category>inetutils</category><category>linemode</category><category>slc</category><category>buffer-overflow</category><category>pre-auth</category><category>cwe-120</category><category>cwe-787</category></item><item><title>Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</guid><description>Critical severity — web · CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11). Status: PoC. Affects: Discuz! X5.0 (PHP-based forum/CMS software). Tags: discuz, php, forum, race-condition, captcha-bypass, ocr, account-takeover, lfi, webshell, rce, pre-auth.</description><category>web</category><category>Critical</category><category>discuz</category><category>php</category><category>forum</category><category>race-condition</category><category>captcha-bypass</category><category>ocr</category><category>account-takeover</category><category>lfi</category><category>webshell</category><category>rce</category><category>pre-auth</category></item><item><title>Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-28_cve-2026-20253-splunk-preauth-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-28_cve-2026-20253-splunk-preauth-rce/</guid><description>Critical severity — web · CVE-2026-20253. Status: PoC. Affects: Splunk Enterprise. Tags: pre-auth, RCE, PostgreSQL, Splunk, CISA-KEV, lo-export, sidecar, unauthenticated, file-write.</description><category>web</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>PostgreSQL</category><category>Splunk</category><category>CISA-KEV</category><category>lo-export</category><category>sidecar</category><category>unauthenticated</category><category>file-write</category></item><item><title>Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-10520, CVE-2026-10523. Status: PoC. Affects: Ivanti Sentry (formerly MobileIron Sentry). Tags: pre-auth, RCE, OS-command-injection, Ivanti, Sentry, MICS-API, auth-bypass, admin-creation, CISA-KEV.</description><category>network</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>OS-command-injection</category><category>Ivanti</category><category>Sentry</category><category>MICS-API</category><category>auth-bypass</category><category>admin-creation</category><category>CISA-KEV</category></item><item><title>Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-dos-flight-deserialization/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-dos-flight-deserialization/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-23870. Status: Weaponized. Affects: Next.js App Router (React server-action / RSC reply parser). Tags: DoS, RSC, React-Flight, deserialization, cyclic-payload, Next.js, App-Router, unauthenticated, pre-auth.</description><category>web</category><category>High</category><category>DoS</category><category>RSC</category><category>React-Flight</category><category>deserialization</category><category>cyclic-payload</category><category>Next.js</category><category>App-Router</category><category>unauthenticated</category><category>pre-auth</category></item><item><title>Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_ivanti-connect-secure-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_ivanti-connect-secure-rce/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-0282. Status: Weaponized. Affects: Ivanti Connect Secure, Ivanti Policy Secure, Ivanti ZTA Gateways. Tags: RCE, stack-overflow, buffer-overflow, pre-auth, unauthenticated, VPN, zero-day, active-exploitation, Ivanti, TLS.</description><category>network</category><category>Critical</category><category>RCE</category><category>stack-overflow</category><category>buffer-overflow</category><category>pre-auth</category><category>unauthenticated</category><category>VPN</category><category>zero-day</category><category>active-exploitation</category><category>Ivanti</category><category>TLS</category></item><item><title>Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-32433. Status: Patched. Affects: Erlang/OTP SSH server daemon. Tags: RCE, pre-auth, unauthenticated, SSH, Erlang, OTP, RabbitMQ, CouchDB, ICS, OT, reverse-shell, in-the-wild.</description><category>network</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>SSH</category><category>Erlang</category><category>OTP</category><category>RabbitMQ</category><category>CouchDB</category><category>ICS</category><category>OT</category><category>reverse-shell</category><category>in-the-wild</category></item><item><title>Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</guid><description>Critical severity — web · CVE-2026-23918. Status: Weaponized. Affects: Apache HTTP Server (httpd) with mod_http2. Tags: RCE, pre-auth, unauthenticated, double-free, heap-corruption, Apache, httpd, mod_http2, HTTP/2, TLS.</description><category>web</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>double-free</category><category>heap-corruption</category><category>Apache</category><category>httpd</category><category>mod_http2</category><category>HTTP/2</category><category>TLS</category></item></channel></rss>