Executive brief
Adminer, a database management tool, contains a flaw in its optional Elasticsearch driver that allows unauthenticated attackers to send HTTP requests to internal hosts and ports on the network. An attacker can exploit this to scan internal networks, fingerprint services, and gather information about internal systems without needing valid login credentials. The vulnerability is only present if the Elasticsearch driver is explicitly enabled and PHP's allow_url_fopen setting is active.
Technical details
Pre-authentication SSRF in the Elasticsearch driver (plugins/drivers/elastic.php) caused by invoking Driver::connect() before login validation in auth.inc.php. An attacker controls auth[server], auth[username], and auth[password] parameters to trigger an HTTP GET request via file_get_contents() to arbitrary hosts on accessible ports (1024+, or default 9200). Error responses and connection failures are rendered on the login page, enabling port scanning and service reconnaissance; exploitation requires explicit driver deployment and allow_url_fopen enabled.
Affected products
- Adminer Project Adminer 4.16.0 through 6.0.1
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Fixed in version 6.0.2