Tag
medium
advisory
Poweradmin Vulnerable to Host Header Injection in Authentication Redirects
3 TTPs 1 CVE 1 IOCPoweradmin versions earlier than 4.2.4 and from 4.3.0 up to, but not including, 4.3.3 are vulnerable to CVE-2026-54588, a critical Host Header Injection flaw in OIDC, SAML, and logout authentication flows that allows an unauthenticated attacker to manipulate the HTTP_HOST header, poisoning callback URLs to redirect authorization codes to an attacker-controlled server, leading to full account takeover and potential full DNS zone control.
Poweradmin +1
web-vulnerability
host-header-injection
oidc
saml
account-takeover
dns-hijacking
3t
1c
1i
high
advisory
Tandoor Recipes Host Header Injection Vulnerability (CVE-2026-33149)
2 rules 1 TTPTandoor Recipes versions up to 2.5.3 use a wildcard for ALLOWED_HOSTS, making Django accept any HTTP Host header without validation, which allows an attacker to manipulate server-generated absolute URLs and potentially compromise user accounts through invite link poisoning.
Tandoor Recipes
host-header-injection
cve-2026-33149
web-application
2r
1t