CVE-2026-88617: SmartAdmin vulnerability
Published Sep 15, 2026
·Updated
SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.
Affected Software
1 affected component
SmartAdmin=3.30.0
Event History
Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as remotely exploitable through the configuration query endpoint. The available information does not state whether authentication is required before reaching that endpoint.
2
How can I determine whether my deployment is affected?
Deployments running SmartAdmin v3.30.0 should be considered affected based on the available information. No configuration-specific conditions or unaffected versions are provided.