PT-2026-99368 · Adminer · Adminer

·

CVE-2026-100697

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adminer versions 6.0.0 through 6.0.1
Description Pre-authentication server-side request forgery occurs when the official ClickHouse driver plugin plugins/drivers/clickhouse.php is loaded. An unauthenticated attacker can provide auth[driver]=clickhouse and set the auth[server] variable to an arbitrary URL. This causes the server to send an HTTP POST request containing 'SELECT version()' to the specified host. Within the rootQuery() function, if the target returns an HTTP status code outside the 200-299 range (excluding 401 and 403), the raw HTTP response body is assigned to the connection error and displayed on the login page. This allows for internal network and port reconnaissance, as well as the disclosure of sensitive information such as stack traces, internal hostnames, file paths, and configuration identifiers found in internal error pages.
Recommendations Update to version 6.0.2. As a temporary mitigation, avoid loading the plugins/drivers/clickhouse.php driver plugin.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100697
GHSA-77QQ-Q8FV-X45V

Affected Products

Adminer