PatchSiren cyber security CVE debrief
CVE-2026-54588 poweradmin CVE debrief
CVE-2026-54588 is a critical vulnerability in Poweradmin, a web-based DNS administration tool. Versions prior to 4.2.4 and 4.3.3 are affected by an unauthenticated attacker-controlled HTTP_HOST request header vulnerability. This vulnerability allows an attacker to poison the redirect_uri sent to the Identity Provider, causing the IdP to redirect the victim's authorization code to an attacker-controlled server, resulting in full account takeover with no credentials required. The vulnerability has a CVSS score of 9.6 and is considered critical. Versions 4.2.4 and 4.3.3 patch the issue.
- Vendor
- poweradmin
- Product
- Unknown
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-23
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-23
- Advisory updated
- 2026-06-25
Who should care
Administrators and users of Poweradmin versions prior to 4.2.4 and 4.3.3 should be aware of this vulnerability and take immediate action to patch their systems. This vulnerability can be exploited by an unauthenticated attacker, making it a high-priority issue. Additionally, security teams and researchers should be aware of this vulnerability to ensure they are monitoring for potential exploitation attempts.
Technical summary
The vulnerability exists in the OIDC, SAML, and logout authentication flows of Poweradmin. The attacker-controlled HTTP_HOST request header is used as the authoritative source for building callback URLs without any validation. This allows an unauthenticated attacker to redirect the victim's authorization code to an attacker-controlled server, resulting in full account takeover. The vulnerability is patched in versions 4.2.4 and 4.3.3.
Defensive priority
This vulnerability has a high defensive priority due to its critical CVSS score and the potential for unauthenticated exploitation. Immediate patching of affected systems is recommended.
Recommended defensive actions
- Patch Poweradmin to version 4.2.4 or 4.3.3
- Monitor for potential exploitation attempts
- Review and update authentication flows to ensure secure configuration
- Implement additional security measures, such as web application firewalls and intrusion detection systems
- Conduct thorough vulnerability assessments and penetration testing
Evidence notes
The evidence for this vulnerability comes from the NVD and CVE.org. The vulnerability is considered critical with a CVSS score of 9.6. The affected versions are prior to 4.2.4 and 4.3.3. The vulnerability is patched in versions 4.2.4 and 4.3.3.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54588 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54588
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54588 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54588
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/poweradmin/poweradmin/releases/tag/v4.2.4
-
Source reference
Unverified legacy reference
URL: https://github.com/poweradmin/poweradmin/releases/tag/v4.3.3
-
Source reference
Unverified legacy reference
URL: https://github.com/poweradmin/poweradmin/security/advisories/GHSA-3735-5339-xfwx
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.