CVE-2026-54588Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthenticated attacker can poison the `redirect_uri` sent to the Identity Provider, causing the IdP to redirect the victim's authorization code to an attacker-controlled server - resulting in full account takeover with no credentials required. Versions 4.2.4 and 4.3.3 patch the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-06-24); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-06-23: 2Mentions · 2026-06-24: 3Mentions · 2026-07-02: 1Mentions · 2026-07-26: 1Patch / Workaround · 2026-06-24: 2Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-26: 1Technical Details · 2026-06-23: 2Technical Details · 2026-06-24: 3Technical Details · 2026-07-02: 1Technical Details · 2026-07-26: 106-2306-2407-0207-26
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-232
Disclosure2
2026-06-243
Disclosure2Patch1
2026-07-021
Patch1
2026-07-261
Patch1
Full discourse7 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A critical Poweradmin host header injection flaw (CVE-2026-54588) lets attackers hijack DNS admin accounts. Update to 4.2.4 or 4.3.3 now. #Poweradmin #PowerDNS #CVE202654588 #AccountTakeover #CyberSecurity #DNS https://securityonline.info/poweradmin-host-header-injection https://t.co/1i4mLYIoBk

    Post summary

    A critical Poweradmin host header injection flaw allows attackers to hijack DNS admin accounts, and users are urged to update to 4.2.4 or 4.3.3 immediately.

    01071790
    12.9K followersView on X
  • John smith@Johnsmithwjvmqq
    Patch

    A critical Poweradmin host header injection flaw (CVE-2026-54588) lets attackers hijack DNS admin accounts. Update to 4.2.4 or 4.3.3 now. #Poweradmin #PowerDNS #CVE202654588 #AccountTakeover #CyberSecurity #DNS http://securityonline.info/poweradmin-hos… https://t.co/Z4JIeibiDB

    Post summary

    The tweet reports a critical host header injection flaw (CVE-2026-54588) in Poweradmin that permits DNS admin account takeover and urges users to apply the 4.2.4 or 4.3.3 update.

    0000058
    58 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-54588 - Critical OIDC/SAML redirect_uri poisoning in #Poweradmin. Unauthenticated attacker can steal auth codes via HTTP_HOST header injection. #CVSS 9.6. #CVEAlert #infosec #cybersecurity #devsecops #sysadmin More FREE detailed info: https://www.valtersit.com/cve/CVE-2026-54588

    Post summary

    The tweet discloses CVE-2026‑54588, a critical OIDC/SAML redirect_uri poisoning flaw in Poweradmin that lets unauthenticated attackers steal auth codes via HTTP_HOST header injection; it provides technical details but no patch, PoC, or evidence of active exploitation.

    0000085
    962 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Poweradmin Host header injection enables OIDC/SAML redirect poisoning (CVE-2026-54588) Poweradmin (web-based DNS admin for PowerDNS) improperly uses the attacker-controlled HTTP_HOST header to build callback URLs in OIDC, SAML, and logout authentication flows. The root cause is improper input validation/trust of Host headers, leading to an authentication redirect URI poisoning issue. An unauthenticated attacker can send crafted requests with a malicious Host value so the redirect_uri sent to the Identity Provider points to attacker infrastructure, causing the victim’s authorization code to be delivered to the attacker. If exploited, this can result in full account takeover and unauthorized access to DNS administration capabilities. 👉 Affected: poweradmin < 4.2.4 and 4.3.0–4.3.2 | Upgrade to 4.2.4 or 4.3.3

    Post summary

    CVE-2026-54588 is a critical host header injection in Poweradmin that can poison OIDC/SAML redirect URIs, enabling full account takeover. Patching to 4.2.4 or 4.3.3 resolves the flaw.

    0000063
    226 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-54588 (CVSS 9.6) Poweradmin DNS tool vulnerable to account takeover via HTTP Host header poisoning in OIDC/SAML flows. Affects versions &lt;4.2.4 &amp; &lt;4.3.3. Patch immediately! #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/Ao8apjIN9h

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-54588) in Poweradmin DNS and urges users to apply the patch immediately.

    0000074
    50 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54588 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the… https://www.cve.org/CVERecord?id=CVE-2026-54588 ----- Traducción: CVE-2026-54588 Pow… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑54588 affecting Poweradmin before v4.2.4/v4.3.3, noting that attacker‑controlled HTTP_HOST header is used, but no PoC, exploit, patch, or active exploitation info is provided.

    0000036
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54588 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the… https://www.cve.org/CVERecord?id=CVE-2026-54588

    Post summary

    The text announces CVE‑2026‑54588, noting that older Poweradmin versions improperly rely on the HTTP_HOST header, thereby disclosing a vulnerability but providing no PoC, exploit, or patch details.

    00000674
    57.7K followersView on X

Explore more