Description
SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Apply Update
AI Analysis

Impact

SmartAdmin version 3.30.0 contains an authorization flaw in its configuration query endpoint. The flaw allows a remote attacker who can reach that endpoint to bypass built‑in authorization checks and gain elevated privileges. By exploiting this weakness, the attacker can read or alter critical configuration data, potentially creating a foothold for further malicious operations. This vulnerability is an example of improper access control and a failure to enforce proper authorization on public endpoints (CWE‑863).

Affected Systems

The affected product is SmartAdmin 3.30.0, specifically the configuration query API endpoint. No other version ranges are indicated in the CNA data, so any installation identified as running 3.30.0 should verify its version and consider upgrading if a fix is released.

Risk and Exploitability

The vulnerability has a CVSS score of 9.8, indicating a high severity of remote privilege escalation. The EPSS score is below 1 %, suggesting a low likelihood of exploitation, but not impossible, especially if the endpoint is publicly reachable. Based on the description, it is inferred that the flaw may be exploitable by any remote user who can reach the configuration endpoint, although the CVE does not explicitly state whether authentication is required. The issue is not listed in CISA’s KEV catalog, but due to its severe impact it remains a priority for immediate remediation.

Generated by OpenCVE AI on September 20, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SmartAdmin to a patched version or a later release that contains the fix
  • Restrict network access to the configuration API by configuring firewalls or reverse proxies to allow only trusted hosts
  • Monitor API usage logs for anomalous configuration queries and investigate suspicious activity

Generated by OpenCVE AI on September 20, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unauthorized Configuration Query in SmartAdmin v3.30.0

Sun, 20 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unauthorized Configuration Query in SmartAdmin v3.30.0
Weaknesses CWE-284

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Authorization Flaw in SmartAdmin Configuration Endpoint

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Authorization Flaw in SmartAdmin Configuration Endpoint
Weaknesses CWE-284

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T16:34:58.492Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88617

cve-icon Vulnrichment

Updated: 2026-09-16T16:34:45.936Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:25.030

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-88617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T19:45:02Z

Weaknesses