
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1196 is an information disclosure vulnerability affecting MineAdmin versions 1.x and 2.x, a backend management system built on the Hyperf framework. The vulnerability exists in the /system/getFileInfoById endpoint, where manipulation of the id argument allows authenticated attackers to enumerate file metadata and subsequently download arbitrary files. It was published on January 19, 2026, with the vendor contacted but unresponsive to disclosure. CVSS v3.1 base score is 5.3 (Medium) per NIST NVD, while the CNA (VulDB) rates it 3.1 (Low) (NVD, GitHub PoC).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-284 (Improper Access Control), stemming from insufficient authorization checks on the /system/getFileInfoById endpoint (NVD). Because the file id parameter is an auto-incrementing integer, an authenticated attacker can enumerate IDs sequentially to retrieve file metadata including cryptographic hashes. These hashes can then be passed to the /system/showFile/{hash} endpoint to preview files or to /system/downloadByHash?hash= to download them, effectively enabling arbitrary file read (GitHub PoC). Exploitation requires network access, low-level authentication, and high attack complexity, with no user interaction needed.
Successful exploitation allows an authenticated attacker with low privileges to enumerate and read arbitrary files stored within the MineAdmin system by chaining three endpoints: getFileInfoById, showFile, and downloadByHash. The impact is limited to confidentiality — there is no integrity or availability impact — but sensitive files accessible to the application (e.g., configuration files, uploaded documents) could be exfiltrated (NVD, GitHub PoC). The exposed file hashes could also facilitate further attacks if sensitive credentials or keys are stored in accessible files.
A public proof-of-concept exploit has been disclosed on GitHub, demonstrating the enumeration and file download chain (GitHub PoC). There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.025% (0.000250), indicating a low probability of exploitation in the near term (NVD). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
body="MineAdmin" on Shodan or similar tools, targeting versions 1.x or 2.x./system/getFileInfoById?id=<N> (e.g., id=1, 2, 3...) to retrieve file metadata including file hashes for each stored file.GET /system/getFileInfoById?id=43 HTTP/1.1
Host: <target>:9501/system/showFile/<hash> (e.g., /system/showFile/e10adc3949ba59abbe56e057f20f883e)./system/downloadByHash?hash=<hash> (GitHub PoC)./system/getFileInfoById?id=<incrementing integer> from a single source IP; unusual requests to /system/showFile/ or /system/downloadByHash?hash= endpoints, especially for files not recently uploaded by the requesting user.getFileInfoById endpoint; access log entries for showFile or downloadByHash endpoints from accounts that do not normally access these resources.No official vendor patch is available, as the MineAdmin vendor did not respond to the responsible disclosure (NVD). Recommended mitigations include: (1) implementing strict authorization checks on the /system/getFileInfoById, /system/showFile, and /system/downloadByHash endpoints to ensure users can only access files they are permitted to view; (2) applying network access controls (e.g., firewall rules, WAF rules) to restrict access to these endpoints to trusted IP ranges; (3) enforcing rate limiting on the getFileInfoById endpoint to prevent enumeration; and (4) monitoring access logs for sequential ID enumeration patterns. Organizations should evaluate upgrading to a patched version if one becomes available or consider alternative solutions given the vendor's non-response (GitHub PoC).
The CVE was noted by automated CVE tracking accounts on X (formerly Twitter) and Bluesky shortly after publication. A brief technical write-up was published on infinitsec.net covering the vulnerability mechanics. No significant vendor statements, major security researcher commentary, or broad media coverage has been identified beyond standard CVE aggregation and tracking (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."