CVE-2026-100698: Server-Side Request Forgery (SSRF) in vrana adminer
Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string as the host with an empty port. Because the privileged-port restriction in adminer/include/auth.inc.php inspects only the parsed port, the check is skipped, and the mysqli/mysqlnd client subsequently re-parses host:port from the host string and opens a TCP connection. A remote, unauthenticated attacker who can reach the Adminer login page can submit a crafted value such as 127.0.0.1:80/x to make the server initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated, enabling server-side request forgery and blind internal port scanning (connection refused vs. handshake vs. timeout acts as a liveness oracle). This is a regression that re-opens the bypass fixed in 5.5.0 (GHSA-58cq-mgw2-38m5). Fixed in 6.0.2.
AI Analysis
Technical Summary
Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function, where the port capture group requires digits anchored to the end of the string. If the server string contains a non-digit suffix, the regex fails and returns the entire string as the host with an empty port. The privileged-port restriction only checks the parsed port, so it is bypassed. The mysqli/mysqlnd client then re-parses the host:port from the host string and opens a TCP connection. This enables a remote unauthenticated attacker who can access the Adminer login page to submit crafted values (e.g., 127.0.0.1:80/x) that cause the server to initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated. This allows SSRF and blind internal port scanning. This vulnerability is a regression of a previously fixed issue (GHSA-58cq-mgw2-38m5) and was fixed in Adminer 6.0.2.
Potential Impact
An unauthenticated remote attacker can exploit this vulnerability to perform server-side request forgery, causing the server to initiate TCP connections to arbitrary internal hosts and ports. This can be used for blind internal port scanning and potentially to access internal network resources that are otherwise inaccessible. The vulnerability occurs before authentication, increasing the risk of unauthorized internal network reconnaissance.
Mitigation Recommendations
Upgrade Adminer to version 6.0.2 or later, where this vulnerability is fixed. No other mitigations are indicated as the fix is official and addresses the root cause.
CVE-2026-100698: Server-Side Request Forgery (SSRF) in vrana adminer
Description
Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string as the host with an empty port. Because the privileged-port restriction in adminer/include/auth.inc.php inspects only the parsed port, the check is skipped, and the mysqli/mysqlnd client subsequently re-parses host:port from the host string and opens a TCP connection. A remote, unauthenticated attacker who can reach the Adminer login page can submit a crafted value such as 127.0.0.1:80/x to make the server initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated, enabling server-side request forgery and blind internal port scanning (connection refused vs. handshake vs. timeout acts as a liveness oracle). This is a regression that re-opens the bypass fixed in 5.5.0 (GHSA-58cq-mgw2-38m5). Fixed in 6.0.2.
CVSS v4.0
Score 6.9medium
Affected software
vrana
adminer
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function, where the port capture group requires digits anchored to the end of the string. If the server string contains a non-digit suffix, the regex fails and returns the entire string as the host with an empty port. The privileged-port restriction only checks the parsed port, so it is bypassed. The mysqli/mysqlnd client then re-parses the host:port from the host string and opens a TCP connection. This enables a remote unauthenticated attacker who can access the Adminer login page to submit crafted values (e.g., 127.0.0.1:80/x) that cause the server to initiate TCP connections to arbitrary internal hosts and privileged ports before credentials are validated. This allows SSRF and blind internal port scanning. This vulnerability is a regression of a previously fixed issue (GHSA-58cq-mgw2-38m5) and was fixed in Adminer 6.0.2.
Potential Impact
An unauthenticated remote attacker can exploit this vulnerability to perform server-side request forgery, causing the server to initiate TCP connections to arbitrary internal hosts and ports. This can be used for blind internal port scanning and potentially to access internal network resources that are otherwise inaccessible. The vulnerability occurs before authentication, increasing the risk of unauthorized internal network reconnaissance.
Mitigation Recommendations
Upgrade Adminer to version 6.0.2 or later, where this vulnerability is fixed. No other mitigations are indicated as the fix is official and addresses the root cause.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:39:50.973Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9adf7a7c5410652fd62
Added to database: 09/26/2026, 13:33:33 UTC
Last enriched: 09/26/2026, 13:48:06 UTC
Last updated: 09/27/2026, 04:31:23 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.