DNS Administration Tool Vulnerability in Poweradmin by PowerDNS
CVE-2026-54588

9.6CRITICAL

Key Information:

Vendor

Poweradmin

Vendor
CVE Published:
23 June 2026

What is CVE-2026-54588?

CVE-2026-54588 is a vulnerability identified in the Poweradmin tool, which serves as a web-based DNS administration interface for PowerDNS servers. This tool is designed to facilitate the management of DNS records and configurations, allowing users to perform essential tasks related to domain name system management. The identified vulnerability arises from the improper handling of the HTTP_HOST request header in versions prior to 4.2.4 and 4.3.3. This flaw allows an attacker to manipulate callback URLs in authentication workflows (specifically OIDC and SAML) without proper validation. Consequently, an unauthenticated attacker can redirect the victim's authorization code to a malicious server. The implications of this vulnerability are severe, as it can lead to complete account takeover without necessitating any user credentials.

Potential Impact of CVE-2026-54588

  1. Unauthorized Account Access: The vulnerability enables attackers to gain full control over user accounts associated with the DNS administration tool, which may lead to unauthorized modifications to DNS records, exposing organizations to further attacks.

  2. Data Integrity Risks: By redirecting authorization codes to malicious servers, attackers could alter or corrupt DNS configurations, impacting the integrity of the data processed through the DNS system and potentially redirecting network traffic.

  3. Reputation Damage and Financial Loss: The compromise of administrative accounts can result in significant reputational damage to the organization, as clients and partners may lose trust in the organization's ability to maintain secure systems. Additionally, the costs associated with remediation efforts and potential legal liabilities can lead to substantial financial losses.

Affected Version(s)

poweradmin < 4.2.4 < 4.2.4

poweradmin >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.