CVE-2026-47693 Details
Description
Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV files without sanitizing formula trigger characters (=, +, -, @). When an administrator exports activity logs and opens the resulting CSV in a spreadsheet application (Microsoft Excel, LibreOffice Calc, Google Sheets), any formula stored in a username is executed by the application. This can be used for phishing attacks against administrators or data exfiltration. Versions 4.2.4 and 4.3.3 patch the issue.
A CSV injection vulnerability has been identified in Poweradmin, a web-based DNS administration tool for PowerDNS server. This issue affects versions prior to 4.2.4 and 4.3.0 through 4.3.2. The vulnerability arises because user-controlled data, specifically the username field, is exported to CSV files without proper sanitization of formula trigger characters. As a result, when the exported CSV is opened in a spreadsheet application, any formula in the username is executed. This vulnerability could be exploited for phishing attacks against administrators or for unauthorized data exfiltration.
Users can upgrade to Poweradmin versions 4.2.4 or 4.3.3, both of which address the CSV injection vulnerability in the log export functionality.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/poweradmin/poweradmin/security/advisories/GHSA-3h6h-67x3-cv5x | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/poweradmin/poweradmin/releases/tag/v4.2.4 | [email protected] | Release NotesVendor |
| https://github.com/poweradmin/poweradmin/releases/tag/v4.3.3 | [email protected] | Release NotesVendor |
| https://github.com/poweradmin/poweradmin/security/advisories/GHSA-3h6h-67x3-cv5x | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1236 | Improper Neutralization of Formula Elements in a CSV File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Poweradmin | < 4.2.4 (semver) >= 4.3.0, < 4.3.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion