Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-54588: Poweradmin DNS tool: Unauthenticated account takeover risk
CVE-2026-54588
Summary
The Poweradmin DNS tool has a security flaw that allows an attacker to take control of an account without knowing the password. This is because the tool doesn't properly check the source of some authentication requests. To fix this, update to version 4.2.4 or 4.3.3 or later.
Original title
Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for build...
Original description
Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthenticated attacker can poison the `redirect_uri` sent to the Identity Provider, causing the IdP to redirect the victim's authorization code to an attacker-controlled server - resulting in full account takeover with no credentials required. Versions 4.2.4 and 4.3.3 patch the issue.
nvd CVSS3.1
9.6
Vulnerability type
CWE-20
Improper Input Validation
CWE-601
Open Redirect
Published: 23 Jun 2026 · Updated: 23 Jul 2026 · First seen: 24 Jun 2026