CVE-2026-105324: An HTTP header injection vulnerability was found in the ADM
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
Affected Software
Event History
Frequently Asked Questions
Which ADM versions are affected?
Affected versions are ADM 4.1.0 through 4.3.3.RWC1 and ADM 5.0.0 through 5.1.4.RL21.
Does exploitation require an authenticated ADM account?
No. The issue can be exploited by an unauthenticated remote attacker through a crafted HTTP request.
What capability does successful exploitation provide?
An attacker can use injected headers in the state parameter to abuse the web server's X-Sendfile mechanism and read arbitrary files from the host system.