9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Description
Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthenticated attacker can poison the `redirect_uri` sent to the Identity Provider, causing the IdP to redirect the victim's authorization code to an attacker-controlled server - resulting in full account takeover with no credentials required. Versions 4.2.4 and 4.3.3 patch the issue.
AI Analysis
Host Header Injection vulnerability in Poweradmin's OIDC, SAML, and logout authentication flows
Basic Information
ID
CVE-2026-54588
Source
GitHub_M
Published
Jun 23, 2026 at 22:09
Affected Product
Vendor
poweradmin
Product
poweradmin
Version
< 4.2.4
Affected Versions
poweradmin poweradmin < 4.2.4
poweradmin poweradmin >= 4.3.0, < 4.3.3
poweradmin poweradmin >= 4.3.0, < 4.3.3
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
Poweradmin
Product
Poweradmin
Version
< 4.2.4, >= 4.3.0 and < 4.3.3