Skip to main content

CVE-2026-100698: Server-Side Request Forgery (SSRF) in vrana adminer

0
Medium
Published: 09/26/2026 (09/26/2026, 15:31:21 UTC)
Source: CVE Database V5
Vendor/Project: vrana
Product: adminer

Description

Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string as the host with an empty port. Because the privileged-port restriction in adminer/include/auth.inc.php inspects only the parsed port, the check is skipped, and the mysqli/mysqlnd client subsequently re-parses host:port from the host string and opens a TCP connection. A remote, unauthenticated attacker who can reach the Adminer login page can submit a crafted value such as 127.0.0.1:80/x to make the server initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated, enabling server-side request forgery and blind internal port scanning (connection refused vs. handshake vs. timeout acts as a liveness oracle). This is a regression that re-opens the bypass fixed in 5.5.0 (GHSA-58cq-mgw2-38m5). Fixed in 6.0.2.

CVSS v4.0

Score 6.9medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
Low
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Affected software

vrana

adminer

Affected versions
>=0 <6.0.2
GitHub Actionsmore threats →ai
vrana/adminer
pkg:github/vrana/adminer
Affected versions
>=0 <6.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 13:48:06 UTC

Technical Analysis

Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function, where the port capture group requires digits anchored to the end of the string. If the server string contains a non-digit suffix, the regex fails and returns the entire string as the host with an empty port. The privileged-port restriction only checks the parsed port, so it is bypassed. The mysqli/mysqlnd client then re-parses the host:port from the host string and opens a TCP connection. This enables a remote unauthenticated attacker who can access the Adminer login page to submit crafted values (e.g., 127.0.0.1:80/x) that cause the server to initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated. This allows SSRF and blind internal port scanning. This vulnerability is a regression of a previously fixed issue (GHSA-58cq-mgw2-38m5) and was fixed in Adminer 6.0.2.

Potential Impact

An unauthenticated remote attacker can exploit this vulnerability to perform server-side request forgery, causing the server to initiate TCP connections to arbitrary internal hosts and ports. This can be used for blind internal port scanning and potentially to access internal network resources that are otherwise inaccessible. The vulnerability occurs before authentication, increasing the risk of unauthorized internal network reconnaissance.

Mitigation Recommendations

Upgrade Adminer to version 6.0.2 or later, where this vulnerability is fixed. No other mitigations are indicated as the fix is official and addresses the root cause.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:39:50.973Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9adf7a7c5410652fd62

Added to database: 09/26/2026, 13:33:33 UTC

Last enriched: 09/26/2026, 13:48:06 UTC

Last updated: 09/27/2026, 04:31:23 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses