[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication SYSTEM RCE in Stimulsoft Server 2026.3.1 (Stimulsoft)



0day Rubbish Research Team is publicly disclosing a vulnerability in Stimulsoft 
Server 2026.3.1 (Stimulsoft). The research is published and a proof-of-concept 
is available.

Pre-authentication SYSTEM RCE (CVSS 9.8, pre-authentication)

A default-configuration defect chain combines into a complete unauthenticated 
RCE. The /1/signup endpoint is open by default with email activation disabled, 
so an anonymous attacker registers and immediately receives a Supervisor 
account. The Supervisor uploads a .mrt report template containing an embedded 
C# script. PUT /1/reporttemplates/<id>/run triggers the report-script engine, 
which compiles the script with CSharpCodeProvider in full trust (no AppDomain 
isolation, no CAS sandbox, no class allowlist) and instantiates the report 
class, executing the attacker-controlled constructor. The report task runs in 
the backend service process Stimulsoft.Server.Agent.exe as NT AUTHORITY\SYSTEM. 
No credentials, no SMTP, no administrator action, and no non-default 
configuration are required.

Impact: Full system takeover; the report task executes in the backend service 
process running as NT AUTHORITY\SYSTEM, giving arbitrary code execution with 
the highest Windows privilege.

Advisory: 
https://0day-rubbish.com/blog/stimulsoft-server-unauth-report-script-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/