CVE-2026-102247 PUBLISHED

FastAdmin Database Management database.php unnecessary privileges

Assigner: VulDB
Reserved: 28.09.2026 Published: 29.09.2026 Updated: 29.09.2026

A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 8.5

Product Status

Vendor n/a
Product FastAdmin
Versions
  • Version 1.6.1.20250430 is affected
  • Version 1.6.5.20260602 is affected

Credits

  • baguette168 (VulDB User) reporter

References

Problem Types

  • Execution with Unnecessary Privileges CWE