CVE-2026-88617 Details
Description
SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.
A vulnerability in SmartAdmin version 3.30.0 allows low-privileged authenticated users to access the 'super_password' configuration value through the '/support/config/queryByKey' endpoint. This authorization flaw can lead to unauthorized privilege escalation by allowing an attacker to log in as an administrator, bypassing email verification requirements.
Access to the configuration query endpoint should be restricted to authorized administrators only. Remove sensitive information from general configuration responses, eliminate the use of universal passwords for authentication, and ensure that all login processes include the necessary verification steps. Additionally, rotate the exposed 'super_password' secret in affected installations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/1024-lab/smart-admin | [email protected] | ProductVendor |
| https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-88617.md | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| 1024-lab SmartAdmin | 3.30.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion