Server-Side Request Forgery Vulnerability in Adminer by VRana
CVE-2026-100697
5.3MEDIUM
What is CVE-2026-100697?
The vulnerability found in Adminer versions 6.0.0 and 6.0.1 allows unauthenticated attackers to exploit the ClickHouse driver plugin, enabling pre-authentication server-side request forgery. By manipulating authentication parameters, an attacker can direct the Adminer server to make arbitrary HTTP POST requests, potentially revealing sensitive internal service responses, stack traces, and other confidential information. This poses significant risks, particularly in environments where internal services may expose sensitive configuration details. Users are advised to upgrade to Adminer version 6.0.2 or later to mitigate this risk.
Affected Version(s)
adminer 0 < 6.0.2
adminer 6.0.2
