Executive brief
Poweradmin, a web-based management tool for PowerDNS, contains a security flaw that allows any user with permission to manage at least one DNS zone to modify records in any other zone on the system. In environments where multiple customers or departments share the same server, an attacker could redirect web traffic, disable services, or take over domains they do not own. This bypasses intended access controls and can lead to a complete compromise of DNS integrity for all users on the platform.
Technical details
An Insecure Direct Object Reference (IDOR) exists in the record editing component of Poweradmin. The `RecordManager::editRecord()` function validates user ownership against a provided zone ID (`zid`) but performs the database update using a separate record ID (`rid`) without verifying that the record actually belongs to the validated zone. An authenticated attacker can provide a `zid` they own to pass the permission check while supplying a `rid` belonging to a victim's zone to overwrite its content. This affects both single-record and multi-record save paths in `EditRecordController` and `EditController`. The vulnerability allows for unauthorized modification of record names, types, content, and status (enabled/disabled) across the entire installation.
Affected products
- Poweradmin Poweradmin >= 3.0.0, < 3.9.11; >= 4.0.0, < 4.2.5; >= 4.3.0, < 4.3.4
Timeline
- 2026-07-23: advisory: Initial GitHub Advisory publication
- 2026-07-24: disclosed: Full disclosure of vulnerability details