Junglewise Threat Intelligence

CVE-2026-54588: Poweradmin Host Header Injection in OIDC and SAML flows

CVE-2026-54588 · Severity: critical · CVSS 9.6 · Published 2026-06-23

Technologies: Poweradmin. Vendors: Poweradmin.

Executive brief

Poweradmin, a web-based interface for managing PowerDNS, contains a vulnerability that allows attackers to hijack user accounts. By manipulating web request headers, an attacker can trick the system into sending sensitive login codes to a server they control. This could lead to a full takeover of the DNS management system, allowing an attacker to redirect email, disrupt website traffic, or issue fraudulent security certificates.

Technical details

Poweradmin fails to validate the 'HTTP_HOST' request header when constructing absolute URLs for OIDC redirect_uris, SAML ACS/SLO URLs, and post-logout redirects. The application dynamically builds these URLs using the client-controlled header instead of a trusted base URL configuration. An unauthenticated attacker can poison these flows by spoofing the Host header, causing the Identity Provider (IdP) to send authorization codes or SAML responses to an attacker-controlled endpoint. This vulnerability is present in OidcService::getCallbackUrl(), SamlConfigurationService::getBaseUrl(), and LogoutController::getBaseUrl(). Patches are available in versions 4.2.4 and 4.3.3.

Affected products

  • Poweradmin poweradmin/poweradmin < 4.2.4, >= 4.3.0, < 4.3.3

Timeline

  • 2026-06-07: disclosed
  • 2026-06-23: advisory: NVD published date
  • 2026-07-28: patched: GitHub Advisory published date

References

Related threats