Description
A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.
Published: 2026-09-29
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Unnecessary Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A flaw in the database.php component of FastAdmin allows a remote attacker to manipulate an unknown function and execute actions with privileges that are not required for normal operation. The impact is a privilege escalation that could compromise the integrity and confidentiality of the database and any data stored therein. The weakness is classified as Privilege Escalation (CWE-250).

Affected Systems

FastAdmin versions 1.6.1.20250430 and 1.6.5.20260602 are affected. The vulnerability resides in the Database Management module and may affect any installation using these releases.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, and the EPSS score is not available, meaning publicly shared exploitation data is limited. The exploit is publicly documented and can be launched remotely. Because no official patch or workaround is listed, the risk remains high for any deployed instance without mitigation. The vulnerability’s nature suggests that an attacker could use the unnecessary privileges to alter or delete database content, elevate internal accounts, or compromise other system components that rely on the database. Given that the vulnerability appears in a core module, the likelihood of exploitation is significant when exposed to the internet.

Generated by OpenCVE AI on September 29, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official FastAdmin patch that removes the unnecessary privilege escalation flaw
  • Configure the database user that the FastAdmin application uses to the least privilege principle, ensuring it only has the minimum permissions required for normal operations
  • Isolate the FastAdmin application from direct exposure to untrusted networks and monitor database logs for abnormal activity

Generated by OpenCVE AI on September 29, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.
Title FastAdmin Database Management database.php unnecessary privileges
First Time appeared Fastadmin
Fastadmin fastadmin
Weaknesses CWE-250
CPEs cpe:2.3:a:fastadmin:fastadmin:*:*:*:*:*:*:*:*
Vendors & Products Fastadmin
Fastadmin fastadmin
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Fastadmin Fastadmin
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-29T03:15:14.129Z

Reserved: 2026-09-28T19:01:16.248Z

Link: CVE-2026-102247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T04:17:54.110

Modified: 2026-09-29T04:17:54.110

Link: CVE-2026-102247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T04:30:12Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges