Unknown · Poweradmin · CVE-2026-54588
**Name of the Vulnerable Software and Affected Versions**
Poweradmin versions prior to 4.2.4
Poweradmin versions prior to 4.3.3
**Description**
Poweradmin is a web-based DNS administration tool for PowerDNS server. The software uses the attacker-controlled `HTTP HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without validation. An unauthenticated attacker can poison the `redirect uri` sent to the Identity Provider, causing the Identity Provider to redirect the victim's authorization code to an attacker-controlled server, which can lead to full account takeover without requiring credentials.
**Recommendations**
Update to version 4.2.4
Update to version 4.3.3