Someone has created a working PoC for both v7 and v6 and shared a demo video, but they haven’t released the actual exploit code. The demo also shows that logging in as user -2 is not required, CVE-2026-86060 can apparently execute commands directly without first creating a user.