CVE-2026-102247: FastAdmin Database Management database.php unnecessary privileges
A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments are known to be affected?
The affected component is Database Management in FastAdmin versions 1.6.1.20250430 and 1.6.5.20260602. The issue involves an unknown function in application/database.php.
Can this be exploited remotely?
Yes. The vulnerability can be attacked remotely, although the provided information does not specify the required authentication level or exact request path.
Is public exploit code available?
Yes. The exploit is reported as public and may be used.
What is the potential impact of successful exploitation?
Successful manipulation can result in execution with unnecessary privileges. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.