{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/adminer-6.0.0-6.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adminer:adminer:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:adminer:adminer:6.0.1:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-100697"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Adminer (6.0.0-6.0.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","ssrf","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Adminer"],"content_html":"\u003cp\u003eAdminer versions 6.0.0 through 6.0.1 contain a critical pre-authentication Server-Side Request Forgery (SSRF) vulnerability when the ClickHouse driver plugin (plugins/drivers/clickhouse.php) is active. The vulnerability stems from improper validation of the 'auth[server]' parameter during the login process. An unauthenticated attacker can submit a crafted HTTP request with 'auth[driver]=clickhouse' and a custom 'auth[server]' URL, forcing the Adminer server to issue an HTTP POST request containing 'SELECT version()' to the target host.\u003c/p\u003e\n\u003cp\u003eWhen the destination service returns an error status (outside the 200-299 range, excluding 401/403), the Adminer application captures the raw response body and renders it directly on the login page. This behavior allows attackers to perform internal network reconnaissance, scan for open ports, and exfiltrate sensitive information, including internal hostnames, configuration details, and stack traces found in error messages. The vulnerability was addressed in Adminer 6.0.2.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to map internal network infrastructure and disclose potentially sensitive metadata or configuration information from internal services unreachable from the public internet. This exposure can lead to further exploitation of internal-only systems, lateral movement, or the acquisition of credentials and configuration identifiers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Adminer to version 6.0.2 or later immediately to patch CVE-2026-100697.\u003c/li\u003e\n\u003cli\u003eFor environments where upgrading is delayed, use a Web Application Firewall (WAF) to block requests containing 'auth[driver]=clickhouse' where the 'auth[server]' parameter targets internal RFC1918 address spaces.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for high volumes of POST requests to Adminer login pages containing unexpected values in the 'auth[server]' or 'auth[driver]' fields.\u003c/li\u003e\n\u003cli\u003eAudit access logs for requests to the Adminer login endpoint that result in 200 OK responses containing error bodies typically associated with internal service probe responses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T15:12:52Z","date_published":"2026-09-26T15:12:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-adminer-ssrf/","summary":"Adminer versions 6.0.0 through 6.0.1 are vulnerable to a pre-authentication SSRF in the ClickHouse driver, allowing unauthenticated attackers to probe internal networks and exfiltrate sensitive response data.","title":"Unauthenticated Server-Side Request Forgery in Adminer ClickHouse Driver","url":"https://feed.craftedsignal.io/briefs/2026-09-adminer-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Adminer (6.0.0-6.0.1)","version":"https://jsonfeed.org/version/1.1"}