Hack The Box - Management
Pre-auth Java deserialization in OpenAM (CVE-2026-33439) yields a shell as the service account, a GLPI-stored LDAP bind secret decrypts to a password the desktop user reuses, and a sudo rdiff-backup wildcard with a parser quirk mirrors /root.