CVE-2026-1196: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-1196 is an information disclosure vulnerability affecting MineAdmin versions 1.x and 2.x, a backend management system built on the Hyperf framework. The vulnerability exists in the /system/getFileInfoById endpoint, where manipulation of the id argument allows authenticated attackers to enumerate file metadata and subsequently download arbitrary files. It was published on January 19, 2026, with the vendor contacted but unresponsive to disclosure. CVSS v3.1 base score is 5.3 (Medium) per NIST NVD, while the CNA (VulDB) rates it 3.1 (Low) (NVD, GitHub PoC).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-284 (Improper Access Control), stemming from insufficient authorization checks on the /system/getFileInfoById endpoint (NVD). Because the file id parameter is an auto-incrementing integer, an authenticated attacker can enumerate IDs sequentially to retrieve file metadata including cryptographic hashes. These hashes can then be passed to the /system/showFile/{hash} endpoint to preview files or to /system/downloadByHash?hash= to download them, effectively enabling arbitrary file read (GitHub PoC). Exploitation requires network access, low-level authentication, and high attack complexity, with no user interaction needed.

Impact

Successful exploitation allows an authenticated attacker with low privileges to enumerate and read arbitrary files stored within the MineAdmin system by chaining three endpoints: getFileInfoById, showFile, and downloadByHash. The impact is limited to confidentiality — there is no integrity or availability impact — but sensitive files accessible to the application (e.g., configuration files, uploaded documents) could be exfiltrated (NVD, GitHub PoC). The exposed file hashes could also facilitate further attacks if sensitive credentials or keys are stored in accessible files.

Exploitability

A public proof-of-concept exploit has been disclosed on GitHub, demonstrating the enumeration and file download chain (GitHub PoC). There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.025% (0.000250), indicating a low probability of exploitation in the near term (NVD). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing MineAdmin instances using asset discovery queries such as body="MineAdmin" on Shodan or similar tools, targeting versions 1.x or 2.x.
  2. Authentication: Obtain low-privilege credentials to the MineAdmin backend (e.g., via phishing, credential stuffing, or default credentials).
  3. Enumerate file IDs: Send sequential GET requests to /system/getFileInfoById?id=<N> (e.g., id=1, 2, 3...) to retrieve file metadata including file hashes for each stored file.
    GET /system/getFileInfoById?id=43 HTTP/1.1
    Host: <target>:9501
  4. Preview file content: Use the retrieved hash to access the file preview endpoint: /system/showFile/<hash> (e.g., /system/showFile/e10adc3949ba59abbe56e057f20f883e).
  5. Download arbitrary files: Pass the hash to the download endpoint to exfiltrate the file: /system/downloadByHash?hash=<hash> (GitHub PoC).

Indicators of compromise

  • Network: Repeated sequential GET requests to /system/getFileInfoById?id=<incrementing integer> from a single source IP; unusual requests to /system/showFile/ or /system/downloadByHash?hash= endpoints, especially for files not recently uploaded by the requesting user.
  • Logs: Web/application access logs showing enumeration patterns (e.g., id=1 through id=N in rapid succession) against the getFileInfoById endpoint; access log entries for showFile or downloadByHash endpoints from accounts that do not normally access these resources.
  • Behavioral: Authenticated low-privilege accounts accessing file metadata or downloading files outside of normal business hours or at high frequency (GitHub PoC).

Mitigation and workarounds

No official vendor patch is available, as the MineAdmin vendor did not respond to the responsible disclosure (NVD). Recommended mitigations include: (1) implementing strict authorization checks on the /system/getFileInfoById, /system/showFile, and /system/downloadByHash endpoints to ensure users can only access files they are permitted to view; (2) applying network access controls (e.g., firewall rules, WAF rules) to restrict access to these endpoints to trusted IP ranges; (3) enforcing rate limiting on the getFileInfoById endpoint to prevent enumeration; and (4) monitoring access logs for sequential ID enumeration patterns. Organizations should evaluate upgrading to a patched version if one becomes available or consider alternative solutions given the vendor's non-response (GitHub PoC).

Community reactions

The CVE was noted by automated CVE tracking accounts on X (formerly Twitter) and Bluesky shortly after publication. A brief technical write-up was published on infinitsec.net covering the vulnerability mechanics. No significant vendor statements, major security researcher commentary, or broad media coverage has been identified beyond standard CVE aggregation and tracking (NVD).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management