CVE-2026-1194: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-1194 is an information disclosure vulnerability affecting the Swagger component of MineAdmin versions 1.x and 2.x. The flaw allows unauthenticated remote attackers to access sensitive API documentation and configuration data exposed through an unprotected Swagger endpoint. It was published on January 19, 2026, with a public exploit released shortly after. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NIST NVD, while the CNA (VulDB) rates it 5.3 (Medium) under CVSS v3.1 (NVD, GitHub PoC). The vendor was contacted prior to disclosure but did not respond (NVD).

Technical details

The root cause is improper access control (CWE-284) combined with exposure of sensitive information to unauthorized actors (CWE-200) in MineAdmin's default deployment configuration. MineAdmin is built on the Hyperf PHP framework, and in its default configuration, the Swagger API documentation endpoint (/swagger/http.json) is publicly accessible without any authentication or authorization checks. An attacker can send a simple unauthenticated HTTP GET request to this endpoint to retrieve the full Swagger/OpenAPI specification, which may expose internal API routes, parameter structures, authentication mechanisms, and other sensitive backend details (GitHub PoC, NVD).

Impact

Successful exploitation results in unauthorized disclosure of sensitive API documentation, including internal endpoint paths, request/response schemas, and potentially authentication-related parameters. This information can significantly aid attackers in mapping the application's attack surface, identifying additional vulnerabilities, and crafting targeted attacks against the backend management system. The impact is limited to confidentiality — there is no direct integrity or availability impact — but the exposed data can serve as a stepping stone for further compromise of the MineAdmin instance and underlying infrastructure (NVD, GitHub PoC).

Exploitability

A public proof-of-concept exploit was released on January 8, 2026, and is available via a GitHub issue tracker (GitHub PoC). The exploit requires no authentication, no special privileges, and no user interaction — a single HTTP GET request is sufficient. The EPSS score is approximately 0.03%, indicating a currently low probability of widespread automated exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (NVD).

Exploitation steps

  1. Reconnaissance: Use asset discovery tools or search engines (e.g., Fofa, Shodan) with the syntax body="MineAdmin" to identify internet-facing MineAdmin instances running versions 1.x or 2.x.
  2. Confirm target: Verify the target is running a vulnerable MineAdmin version by checking the application's login page or HTTP response headers for identifying information.
  3. Send exploit request: Issue an unauthenticated HTTP GET request to the Swagger endpoint:
GET /swagger/http.json HTTP/1.1
Host: <target-host>
  1. Harvest disclosed information: Parse the returned JSON response, which contains the full OpenAPI/Swagger specification — including all API routes, parameter names, data types, and potentially authentication endpoint details.
  2. Leverage for further attacks: Use the harvested API map to identify additional attack vectors, such as unprotected administrative endpoints, injection points, or authentication bypass opportunities (GitHub PoC, NVD).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /swagger/http.json from external or unexpected IP addresses; high volume of requests to this endpoint from a single source.
  • Logs: Web server or application access logs showing GET /swagger/http.json with HTTP 200 responses from non-internal IP addresses; absence of authentication headers in requests to the Swagger endpoint.
  • Application: Subsequent probing of internal API endpoints discovered via the Swagger specification, particularly from the same source IP that accessed /swagger/http.json (GitHub PoC).

Mitigation and workarounds

No official vendor patch has been released, as the MineAdmin vendor did not respond to the disclosure (NVD). The recommended workaround is to restrict access to the Swagger endpoint (/swagger/http.json) by implementing authentication or authorization controls at the application or web server level. Administrators should also consider blocking public access to the Swagger UI entirely in production environments, or using firewall/reverse proxy rules to limit access to trusted IP ranges. Monitoring access logs for requests to the Swagger endpoint is advised as a detection measure (GitHub PoC).

Community reactions

The vulnerability was noted on Bluesky via the CVE tracking account shortly after disclosure. Coverage has been picked up by threat intelligence aggregators including Vulners, CIRCL, and Offseq Radar. A brief technical write-up was published by Infinit Security (Infinit Security). Community sentiment reflects concern over the vendor's lack of response to responsible disclosure, leaving users without an official patch.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management