
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1194 is an information disclosure vulnerability affecting the Swagger component of MineAdmin versions 1.x and 2.x. The flaw allows unauthenticated remote attackers to access sensitive API documentation and configuration data exposed through an unprotected Swagger endpoint. It was published on January 19, 2026, with a public exploit released shortly after. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NIST NVD, while the CNA (VulDB) rates it 5.3 (Medium) under CVSS v3.1 (NVD, GitHub PoC). The vendor was contacted prior to disclosure but did not respond (NVD).
The root cause is improper access control (CWE-284) combined with exposure of sensitive information to unauthorized actors (CWE-200) in MineAdmin's default deployment configuration. MineAdmin is built on the Hyperf PHP framework, and in its default configuration, the Swagger API documentation endpoint (/swagger/http.json) is publicly accessible without any authentication or authorization checks. An attacker can send a simple unauthenticated HTTP GET request to this endpoint to retrieve the full Swagger/OpenAPI specification, which may expose internal API routes, parameter structures, authentication mechanisms, and other sensitive backend details (GitHub PoC, NVD).
Successful exploitation results in unauthorized disclosure of sensitive API documentation, including internal endpoint paths, request/response schemas, and potentially authentication-related parameters. This information can significantly aid attackers in mapping the application's attack surface, identifying additional vulnerabilities, and crafting targeted attacks against the backend management system. The impact is limited to confidentiality — there is no direct integrity or availability impact — but the exposed data can serve as a stepping stone for further compromise of the MineAdmin instance and underlying infrastructure (NVD, GitHub PoC).
A public proof-of-concept exploit was released on January 8, 2026, and is available via a GitHub issue tracker (GitHub PoC). The exploit requires no authentication, no special privileges, and no user interaction — a single HTTP GET request is sufficient. The EPSS score is approximately 0.03%, indicating a currently low probability of widespread automated exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (NVD).
body="MineAdmin" to identify internet-facing MineAdmin instances running versions 1.x or 2.x.GET /swagger/http.json HTTP/1.1
Host: <target-host>/swagger/http.json from external or unexpected IP addresses; high volume of requests to this endpoint from a single source.GET /swagger/http.json with HTTP 200 responses from non-internal IP addresses; absence of authentication headers in requests to the Swagger endpoint./swagger/http.json (GitHub PoC).No official vendor patch has been released, as the MineAdmin vendor did not respond to the disclosure (NVD). The recommended workaround is to restrict access to the Swagger endpoint (/swagger/http.json) by implementing authentication or authorization controls at the application or web server level. Administrators should also consider blocking public access to the Swagger UI entirely in production environments, or using firewall/reverse proxy rules to limit access to trusted IP ranges. Monitoring access logs for requests to the Swagger endpoint is advised as a detection measure (GitHub PoC).
The vulnerability was noted on Bluesky via the CVE tracking account shortly after disclosure. Coverage has been picked up by threat intelligence aggregators including Vulners, CIRCL, and Offseq Radar. A brief technical write-up was published by Infinit Security (Infinit Security). Community sentiment reflects concern over the vendor's lack of response to responsible disclosure, leaving users without an official patch.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."