PT-2026-99369 · Adminer · Adminer

·

CVE-2026-100698

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Adminer versions 5.5.1 through 6.0.1
Description An issue exists in the host port() function within adminer/include/functions.inc.php where the login server string is improperly parsed. The port capture group requires digits anchored to the end of the string; if a server value contains a non-digit tail, the regex fails and the entire string is returned as the host with an empty port. This allows a remote, unauthenticated attacker to bypass the privileged-port restriction in adminer/include/auth.inc.php by submitting a crafted value, such as 127.0.0.1:80/x. Consequently, the mysqli/mysqlnd client re-parses the host and port, enabling server-side request forgery (SSRF) and blind internal port scanning by observing connection responses (connection refused, handshake, or timeout) before credentials are validated.
Recommendations Update to version 6.0.2.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100698
GHSA-RWXG-XPH9-82CJ

Affected Products

Adminer