Sceawere
Vulnerability Detail
CVE-2026-102247UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FastAdmin Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- FastAdmin
- Attack Type
- Execution with Unnecessary Privileges
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-09-29T04:17:54.110Z",
"pubdate": "2026-09-29T04:17:54.110Z",
"executiveSummary": "A critical security vulnerability has been identified in the Database Management component of FastAdmin, specifically impacting versions 1.6.1.20250430 and 1.6.5.20260602.\nThe vulnerability manifests as an improper privilege management flaw located within the application/database.php file.\nThis vulnerability enables remote attackers to execute operations with unnecessary and potentially elevated privileges, bypassing intended access control restrictions.\nThe risk is categorized as high, as the exploit is currently public, significantly lowering the barrier to entry for malicious actors.\nSuccessful exploitation allows an attacker to perform unauthorized actions within the database management interface, potentially leading to full system compromise or unauthorized data manipulation.\nThere are no specific mentions of complex prerequisites for exploitation, suggesting that remote, unauthenticated, or low-privileged attackers could potentially leverage this flaw depending on the specific endpoint exposure.",
"technicalDetails": "The vulnerability resides in the Database Management component of FastAdmin, specifically identified within the application/database.php file. The root cause is an improper authorization check or a failure to enforce the Principle of Least Privilege (PoLP) during database management operations.\nThe flaw allows an attacker to interact with sensitive database administrative functions without possessing the requisite security context or access rights. By manipulating requests directed at this specific file, an attacker can coerce the application into executing commands or accessing data that should be restricted to administrative users.\nThe attack flow begins with the attacker identifying the target endpoint within application/database.php. Since the application fails to validate the initiator's authorization level before executing high-privileged logic, the attacker can transmit a crafted request—likely via HTTP POST or GET—that triggers the vulnerable function. The lack of server-side validation regarding the user session privileges allows the requested operation to proceed.\nExploitation involves sending specifically formatted payloads to the vulnerable file, which likely interprets parameters or input data to construct or execute database queries/management tasks. Because the application processes these requests with unnecessary privileges, the attacker effectively gains the permissions of the underlying service account or the administrative role intended only for authorized personnel.\nPost-exploitation impact is severe. Once unauthorized access is established, an attacker could potentially modify database content, delete critical records, or inject malicious administrative accounts. Furthermore, if the database configuration permits it, an attacker might leverage database-specific features to achieve Remote Code Execution (RCE) on the underlying host, leading to complete infrastructure takeover.\nThe vulnerability is inherently remote in nature, meaning it does not require physical access to the server. The accessibility of the component depends on the exposure of the FastAdmin management interface; however, if the application is publicly accessible, the vulnerability is reachable by any network-adjacent entity."
}