Junglewise Threat Intelligence

CVE-2026-71622: Zhao-github APiAdmin SQL injection in User.php

CVE-2026-71622 · Severity: high · CVSS 7.4 · Published 2026-09-04

Executive brief

APiAdmin is an API administration panel used to manage backend systems and user access. A SQL injection vulnerability in the User.php component allows remote attackers to extract sensitive data directly from the database, potentially exposing user credentials, system configurations, and other confidential information without requiring authentication.

Technical details

This is a SQL injection vulnerability in the User.php component of APiAdmin v5.0.1. The vulnerability allows a remote attacker to inject malicious SQL commands through user-controlled input, likely in query parameters or request body fields. By exploiting this weakness, attackers can extract sensitive information from the database, such as user credentials, API keys, and configuration data. The vulnerability is network-accessible and does not require authentication to exploit. A patch or update addressing this issue should be applied immediately.

Affected products

  • Zhao-github APiAdmin 5.0.1

Timeline

  • 2026-09-04: disclosed

References

Related threats