<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2026-27626 on bokkapig</title><link>https://bokkapig.pages.dev/tags/cve-2026-27626/</link><description>Recent content in CVE-2026-27626 on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Wed, 05 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/cve-2026-27626/index.xml" rel="self" type="application/rss+xml"/><item><title>Enigma</title><link>https://bokkapig.pages.dev/writeups/enigma/</link><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/enigma/</guid><description>A world-readable NFS export (/srv/nfs/onboarding) hands out an onboarding PDF containing kevin&amp;rsquo;s webmail credentials for mail001.enigma.htb; the same default password Enigma2024! works for sarah, whose mailbox holds an IT provisioning email with admin credentials for the internal helpdesk at support_001.enigma.htb. That app is OpenSTAManager 2.9.8, vulnerable to CVE-2025-69212 — an unescaped filename reaching exec() in XML::decodeP7M() via the importFE_ZIP plugin — giving RCE as www-data. config.inc.php leaks the MySQL account brollin:Fri3nds@9099, and the zz_users table yields haris&amp;rsquo;s bcrypt hash, cracked with rockyou to &amp;lsquo;bestfriends&amp;rsquo; for user.txt. Root is a loopback-only OliveTin 3000.10.0 on 127.0.0.1:1337 running as root with anonymous guest execution: its &amp;lsquo;Backup Database&amp;rsquo; action takes a db_pass argument of type password, the one type TypeSafetyCheck never validates (CVE-2026-27626, CVSS 9.9), so shell metacharacters in that field execute as root.</description></item></channel></rss>