A publicly disclosed vulnerability chain in Stimulsoft Server 2026.3.1 allows an unauthenticated attacker to achieve remote code execution as NT AUTHORITY\SYSTEM under the product’s default configuration. According to the advisory, the exposed /1/signup endpoint can grant an anonymous user a Supervisor account when email activation is disabled, creating an initial privilege path without valid credentials, SMTP access, or administrator involvement.
After obtaining Supervisor access, an attacker can upload a malicious .mrt report template containing embedded C# code and trigger it through /1/reporttemplates/<id>/run. The report engine is said to compile and execute the attacker-controlled script in full trust via CSharpCodeProvider, without sandboxing or isolation, causing code to run inside Stimulsoft.Server.Agent.exe with SYSTEM privileges and enabling full host compromise. The issue and proof of concept were published by the 0day Rubbish Research Team and later circulated through Full Disclosure.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The Stimulsoft Server RCE advisory was distributed through the Full Disclosure mailing list, extending public dissemination of the vulnerability details. The mailing list post described the issue as a pre-authentication SYSTEM-level RCE affecting version 2026.3.1.
The 0day Rubbish Research Team publicly disclosed a pre-authentication remote code execution vulnerability in Stimulsoft Server 2026.3.1 that can lead to NT AUTHORITY\SYSTEM code execution under default configuration. The advisory included a proof of concept and full technical analysis describing the signup-to-report-script exploit chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open source0day-rubbish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.