Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersDisclosure
The tweet discloses CVE-2026‑54588, a critical OIDC/SAML redirect_uri poisoning flaw in Poweradmin that lets unauthenticated attackers steal auth codes via HTTP_HOST header injection; it provides technical details but no patch, PoC, or evidence of active exploitation.
Upwind Security MDR[verified]@UpwindMDRDisclosure
CVE-2026-54588 is a critical host header injection in Poweradmin that can poison OIDC/SAML redirect URIs, enabling full account takeover. Patching to 4.2.4 or 4.3.3 resolves the flaw.
DFIR Lab[verified]@DFIR_LabPatch
The tweet announces a critical vulnerability (CVE-2026-54588) in Poweradmin DNS and urges users to apply the patch immediately.
Daily CyberSecurity@the_yellow_fallPatch
A critical Poweradmin host header injection flaw allows attackers to hijack DNS admin accounts, and users are urged to update to 4.2.4 or 4.3.3 immediately.
John smith@JohnsmithwjvmqqPatch
The tweet reports a critical host header injection flaw (CVE-2026-54588) in Poweradmin that permits DNS admin account takeover and urges users to apply the 4.2.4 or 4.3.3 update.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑54588 affecting Poweradmin before v4.2.4/v4.3.3, noting that attacker‑controlled HTTP_HOST header is used, but no PoC, exploit, patch, or active exploitation info is provided.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑54588, noting that older Poweradmin versions improperly rely on the HTTP_HOST header, thereby disclosing a vulnerability but providing no PoC, exploit, or patch details.