
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25878 is a missing authentication vulnerability in FroshAdminer (frosh/adminer-platform), the Adminer database management plugin for the Shopware Platform. The Adminer route (/admin/adminer) was configured with auth_required=false and performed no session validation, allowing unauthenticated users to access the Adminer UI directly. All versions prior to 2.2.1 are affected. The advisory was published by the maintainer on February 7, 2026, and added to the NVD on February 9, 2026. The CVSS v3.1 base score is 5.3 (Medium), while the CVSS v4.0 base score is 6.9 (Medium) (GitHub Advisory, FroshPlatformAdminer Advisory).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function). The AdminerController.php index() method, which renders the Adminer UI, was registered with auth_required=false in the Shopware route defaults and contained no session validation logic, meaning any network-accessible request to GET /admin/adminer would load the full Adminer interface without verifying the requester's identity. The fix introduced in version 2.2.1 adds a session-based check: the login() endpoint sets a frosh_adminer_authenticated flag in the PHP session, and index() now verifies this flag before rendering — returning HTTP 403 Forbidden if absent. Importantly, direct database access is not possible through this vulnerability alone, as database credentials are only set via an ACL-protected API endpoint (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated remote attacker to access the Adminer database management UI without any credentials or user interaction. The primary risk is information disclosure — an attacker can observe the Adminer interface, potentially revealing database server version information, configuration details, and other metadata. Additionally, exposure of the Adminer UI surface increases the attack area for exploitation of any Adminer-specific vulnerabilities (e.g., known Adminer CVEs). Direct database read/write access is not achievable through this vulnerability alone, as database credentials require a prior authenticated admin session to configure (GitHub Advisory, FroshPlatformAdminer Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of reporting (GitHub Advisory). The vulnerability is trivially exploitable by any unauthenticated attacker who can reach the /admin/adminer endpoint over the network, requiring no special tools or credentials. The EPSS score is approximately 0.10% (0.001010), indicating a low probability of exploitation in the near term. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
https://<target>/admin/adminer. Due to auth_required=false and no session validation, the server renders the full Adminer UI without requiring login./admin/adminer from external or unexpected IP addresses in web server access logs./admin/adminer without a preceding authenticated session or login event; absence of a valid Shopware admin session cookie in requests to this endpoint.frosh_adminer_authenticated flag set without a corresponding Shopware admin login event (on unpatched versions, this flag would not exist at all, so any access to the route is inherently unauthenticated).Upgrade FroshAdminer to version 2.2.1 or later, which adds session-based authentication to the /admin/adminer route (Release 2.2.1). For environments unable to upgrade immediately, the recommended workaround is to deactivate or uninstall the FroshAdminer plugin entirely, or restrict network access to the /admin/adminer route at the firewall or web server level (FroshPlatformAdminer Advisory).
The vulnerability was reported by researchers xndrdev and Gugiman and disclosed responsibly through GitHub's security advisory process by maintainer shyim on February 7, 2026 (FroshPlatformAdminer Advisory). No significant broader media coverage or notable community commentary beyond the advisory itself has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."