Server-Side Request Forgery Vulnerability in Adminer by VRana
CVE-2026-100697

5.3MEDIUM

Key Information:

Vendor

Vrana

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100697?

The vulnerability found in Adminer versions 6.0.0 and 6.0.1 allows unauthenticated attackers to exploit the ClickHouse driver plugin, enabling pre-authentication server-side request forgery. By manipulating authentication parameters, an attacker can direct the Adminer server to make arbitrary HTTP POST requests, potentially revealing sensitive internal service responses, stack traces, and other confidential information. This poses significant risks, particularly in environments where internal services may expose sensitive configuration details. Users are advised to upgrade to Adminer version 6.0.2 or later to mitigate this risk.

Affected Version(s)

adminer 0 < 6.0.2

adminer 6.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lichoin
.