Poweradmin, a web-based DNS administration tool for PowerDNS server, uses the attacker-controlled HTTP_HOST request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without validation. An attacker can poison the redirect_uri sent to the Identity Provider, causing it to redirect the victim's authorization code to an attacker-controlled server.
An unauthenticated attacker over the network can perform account takeover by manipulating the HTTP_HOST header to redirect authorization codes to an attacker-controlled server, gaining full access to any user's Poweradmin account without requiring credentials.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Yes, patch is available in versions 4.2.4 and 4.3.3.
Upgrade Poweradmin to version 4.2.4 or 4.3.3 or later. Additionally, implement network-level controls to restrict or validate the HTTP_HOST header where possible, and consider implementing strict redirect URI validation at the Identity Provider level if configurable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Feedly found the first article mentioning CVE-2026-54588 . See article
NVD published the first details for CVE-2026-54588
A CVSS base score of 9.6 has been assigned.
RedHat CVE advisory released a security advisory ( CVE-2026-54588 ) .
A critical vulnerability in Poweradmin allows unauthenticated attackers to exploit the HTTP_HOST request header, enabling them to redirect authorization codes to their own servers, potentially leading to full account takeover without credential requirements. Red Hat Product Security has assessed that this vulnerability does not affect any currently supported Red Hat products, and there are no details on proof-of-concept exploits, mitigations, or patches provided in the article. Further analysis may evolve the understanding of its impact on other third-party vendors or technologies. See article
CVE-2026-54588: Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. [CRITICAL] CVSS 9.6
CVE-2026-54588 | Poweradmin up to 4.2.3/4.3.2 input validation (GHSA-3735-5339-xfwx)
CVE-2026-54588 - Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. CVE ID : CVE-2026-54588 Published : June 23, 2026, 10:09 p.m. | 1 hour, 34 minutes ago Description : Poweradmin is a web-based DNS administrati...
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
