DNS Administration Tool Vulnerability in Poweradmin by PowerDNS
⚠️ CVE-Referenzen:
CVE-2026-54588
Poweradmin - Poweradmin - CRITICAL - CVE-2026-54588.
Poweradmin, a web-based DNS administration tool for PowerDNS, is vulnerable due to improper validation of the `HTTP_HOST` request header. This flaw allows an unauthenticated attacker to manipulate the `redirect_uri` in OIDC, SAML, and logout flows used during authentication. By redirecting the authorization code to a malicious server, attackers can achieve full account takeover without needing the victim's credentials. It is crucial for users of Poweradmin to upgrade to versions 4.2.4 or 4.3.3, which address this security issue.
Quelle: securityvulnerability.io