poweradmin has 5 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 8.1 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 4 prev 1
Weakness classes
Products
- poweradmin/poweradmin 5
Worst active — by depth score
CVE-2026-54588Critical· 9.6Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.53GHSA-h4hf-v6w5-897xHigh· 8.8Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account48GHSA-rm67-g9ch-vxffHigh· 8.1Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own45GHSA-cmwh-g2h8-c222High· 8.1Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover45CVE-2026-47693Medium· 6.9Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications38
poweradmin vulnerabilities
CVEs affecting poweradmin, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-54588Critical· 9.6Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
GHSA-h4hf-v6w5-897xHigh· 8.8Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
GHSA-rm67-g9ch-vxffHigh· 8.1Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
GHSA-cmwh-g2h8-c222High· 8.1Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
CVE-2026-47693Medium· 6.9Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications