PT-2026-99367 · Adminer · Adminer

·

CVE-2026-100696

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Adminer versions 4.16.0 through 6.0.1
Description A pre-authentication Server-Side Request Forgery (SSRF) exists in the optional Elasticsearch driver located at plugins/drivers/elastic.php. The issue occurs because adminer/include/auth.inc.php calls the Driver::connect() function before validating the login result. An unauthenticated attacker can send crafted auth[server], auth[username], and auth[password] parameters to force the server to issue an HTTP GET request via get url() or file get contents() to an arbitrary reachable host and port. The driver fails to block loopback, private, or link-local addresses, and while it rejects ports below 1024, it appends the default port 9200 if none is provided. This allows for internal network reconnaissance and service fingerprinting, as connection failures and specific JSON error fields from non-2xx responses are displayed on the login page. This requires the Elasticsearch driver to be explicitly deployed and the PHP allow url fopen setting to be enabled.
Recommendations Update to version 6.0.2. Restrict the use of the plugins/drivers/elastic.php driver if it is not required. Disable the PHP allow url fopen setting to mitigate the risk.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100696
GHSA-Q8H3-4CX4-PRGM

Affected Products

Adminer