CVE-2026-102247 Details
Description
A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability exists in FastAdmin versions 1.6.1.20250430 and 1.6.5.20260602, specifically within the official Database Management addon. This vulnerability allows authenticated administrators to execute arbitrary SQL commands with elevated privileges. The issue arises from the addon providing an unrestricted SQL execution console, combined with FastAdmin's default database configuration that connects to the MySQL root account, which has superuser privileges. As a result, an authenticated administrator could exploit this to execute harmful SQL commands, such as injecting PHP code that could be executed on the server, leading to remote code execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/baguette168/CVE/issues/2 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/cve/CVE-2026-102247 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/933377 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411145 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411145/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FastAdmin | >= 1, < 2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion