CVE-2026-1195: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-1195 is a logic flaw (insufficient verification of data authenticity) in the JWT Token Handler of MineAdmin 1.x and 2.x, specifically in the refresh function at the /system/refresh endpoint. The vulnerability allows a remote, low-privileged attacker to forge a JWT signed as a super administrator and obtain a valid new token with administrator privileges. It was published on January 19–20, 2026, with a public proof-of-concept available at the time of disclosure. The vendor was contacted prior to disclosure but did not respond. CVSS v3.1 base score is 7.5 (High) per NIST NVD, while the CNA (VulDB) rates it 5.0 (Medium); CVSS v4.0 is rated 1.3 (Low) by VulDB (VulDB PoC, Red Hat CVE).

Technical details

The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). The refresh method in MineAdmin's JWT Token Handler, located at /system/refresh, fails to properly validate the cryptographic signature of the incoming JWT before issuing a new token. An attacker can craft an arbitrary JWT payload — including claims that set the user as a super administrator (user_type: 100, id: 1) — with any desired expiration time, and submit it to the refresh endpoint without possessing a legitimately signed token. The system accepts the forged token and returns a new, valid, server-issued JWT with administrator privileges. The attack requires network access and low-level authentication context (e.g., any valid account or knowledge of the token format), and is rated high complexity due to the need to construct a valid-looking JWT structure (VulDB PoC).

Impact

Successful exploitation allows an attacker to obtain a legitimate administrator-level JWT token, effectively bypassing all access controls in the MineAdmin backend management system. With super administrator privileges, an attacker can access, modify, or delete sensitive data, manage user accounts, and potentially pivot to other systems or services integrated with the MineAdmin instance. The confidentiality, integrity, and availability of the affected system are all at high risk per NIST's CVSS v3.1 assessment (VulDB PoC, Red Hat CVE).

Exploitability

A public proof-of-concept exploit has been available since at least January 2026, published in a GitHub issue by the researcher SourByte05. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of widespread exploitation. No threat actor attribution or CISA KEV catalog listing has been identified. The CVE status is listed as "Unknown" and no in-the-wild exploitation has been confirmed as of the available data (VulDB PoC, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing MineAdmin instances (v1.x or v2.x) using asset discovery queries such as body="MineAdmin" on tools like Fofa or Shodan. Note the default backend API port (9501).
  2. Craft a forged JWT: Construct a JWT with an arbitrary payload claiming super administrator identity, e.g., {"id": 1, "username": "superAdmin", "user_type": "100", "jwt_scene": "default"} with any desired iat, nbf, and exp values. Sign it with any key (the server does not validate the signature).
  3. Submit to the refresh endpoint: Send a POST request to /system/refresh with the forged JWT in the Authorization: Bearer <token> header and Content-Type: application/json;charset=UTF-8.
  4. Extract the new token: The server responds with a new, legitimately signed JWT granting super administrator privileges. Copy this token from the response.
  5. Abuse administrator access: Use the obtained token to authenticate to the MineAdmin API (e.g., /system/user/info or other admin endpoints) and perform unauthorized actions including data access, user management, or further lateral movement (VulDB PoC).

Indicators of compromise

  • Network: Unexpected POST requests to /system/refresh from IP addresses not associated with legitimate users, especially with JWTs containing user_type: 100 or username: superAdmin claims; repeated token refresh attempts from a single source.
  • Logs: Backend API access logs showing /system/refresh requests followed immediately by privileged API calls (e.g., user management, configuration changes) from the same session; JWT payloads in logs with anomalous iat/exp timestamps (e.g., far-future expiration).
  • Application Behavior: New administrator-level sessions appearing without corresponding login events; unexpected changes to user accounts, permissions, or system configuration shortly after a refresh request (VulDB PoC).

Mitigation and workarounds

The vendor has not responded to disclosure and no official patch has been released as of the available data. The researcher recommends forcing validation of the JWT signature in the refresh method to ensure only tokens signed with the server's secret key are accepted. As a workaround, administrators should restrict network access to the MineAdmin backend API port (default: 9501) to trusted IP ranges, implement rate limiting on the /system/refresh endpoint, and monitor logs for anomalous token refresh activity. Organizations should evaluate upgrading to a patched version if and when one becomes available (VulDB PoC).

Community reactions

The vulnerability was submitted to VulDB by researcher SourByte05, who also published the proof-of-concept on GitHub. The vendor (MineAdmin) did not respond to the coordinated disclosure attempt. Red Hat has tracked the CVE in their security advisory database. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Red Hat CVE, VulDB PoC).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management