{"id":"CVE-2026-100696","summary":"Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver","details":"Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php invokes Driver::connect() before the login result is validated, an unauthenticated attacker who submits crafted auth[server], auth[username], and auth[password] parameters can cause the Adminer server to issue an HTTP GET request (via get_url()/file_get_contents()) to an arbitrary reachable host and port. The driver validates only general server syntax and does not block loopback, private, link-local, or other reserved addresses; if no port is given it appends the default 9200, and Adminer's generic port check rejects ports below 1024. Selected JSON error fields from non-2xx Elasticsearch-style responses, as well as connection failures, are rendered on the login page, providing a port-scanning oracle and enabling internal network reconnaissance and service fingerprinting. Exploitation requires that the optional Elasticsearch driver be explicitly deployed (e.g., via the adminer/elastic.php template or an adminer_object() configuration; it is not loaded in a default build) and that PHP allow_url_fopen be enabled.","aliases":["GHSA-q8h3-4cx4-prgm"],"modified":"2026-09-28T03:48:31.130353531Z","published":"2026-09-26T13:23:53.613Z","database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100696.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100696.json"},{"type":"ADVISORY","url":"https://github.com/vrana/adminer/security/advisories/GHSA-q8h3-4cx4-prgm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100696"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/adminer-before-6.0.2-unauthenticated-ssrf-via-elasticsearch-driver"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vrana/adminer","events":[{"introduced":"9c9fc4a85b3b35b059fcf9bf334789c0378becb7"},{"fixed":"bac73e4a126f2e5e82d763da4e233e8ebff82055"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"fixed":"6.0.2"},{"introduced":"4.16.0"},{"fixed":"6.0.1"}]}}],"versions":["v6.0.1","v6.0.0","v5.5.1","v5.5.0","v5.4.4","v5.4.3","v5.4.2","v5.4.1","v5.4.0","v5.3.0","v5.2.1","v5.2.0","v5.1.1","v5.1.0","v5.0.6","v5.0.5","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.17.1","v4.17.0","v4.16.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100696.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"}]}