CVE-2026-55224: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-55224 is a path traversal vulnerability in MineAdmin's app-store plugin service that allows attackers to read, install, or uninstall plugins from arbitrary directories and potentially execute arbitrary Composer commands. It affects all versions of the mineadmin/mineadmin Composer package prior to 3.2.0-alpha.2. The vulnerability was originally reported on June 11, 2026, and published to the GitHub Advisory Database on August 18, 2026. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), where the download(), install(), and unInstall() methods in plugin/mine-admin/app-store/src/Service/Service.php concatenate the user-supplied identifier parameter directly into file system paths without sanitization (e.g., BASE_PATH . '/plugin/' . $params['identifier']). An attacker can supply traversal sequences such as ../ to escape the intended /plugin/ directory and reference arbitrary paths on the server. Compounding the issue, the IndexController controlling these endpoints applied only AccessTokenMiddleware and lacked PermissionMiddleware, meaning any authenticated user — regardless of role — could reach the vulnerable endpoints (GitHub Advisory, MineAdmin Security Advisory).

Impact

Successful exploitation allows an authenticated attacker to install or uninstall plugins from arbitrary directories on the server, probe directory existence outside the plugin root, and potentially trigger Plugin::install() with a traversal path — which may execute Composer commands against arbitrary directories, leading to arbitrary code execution with the privileges of the application process. The integrity of the vulnerable system is the primary concern, as an attacker could manipulate application files or introduce malicious code. Combined with the missing PermissionMiddleware, the attack surface extends to any user holding a valid access token, not just administrators (GitHub Advisory, MineAdmin Security Advisory).

Exploitability

The vulnerability requires a valid access token (authenticated user) but no special permissions, making it exploitable by any logged-in user. A proof-of-concept using curl is included in the public advisory, demonstrating exploitation via crafted JSON payloads to the /admin/plugin/store/install and /admin/plugin/store/download endpoints. A Nuclei detection template was added to the ProjectDiscovery nuclei-templates repository (commit f37500939bfe9d94f69d1070537ded4fa6a9a070, included in release v10.4.8), further lowering the barrier to exploitation. As of the advisory publication date, there is no confirmed evidence of in-the-wild exploitation, and the CVE status remains Reserved. No EPSS score or CISA KEV listing is currently available (GitHub Advisory, Nuclei Templates).

Exploitation steps

  1. Obtain a valid access token: Authenticate to the MineAdmin instance with any valid user account to obtain a Bearer token — no elevated privileges are required due to the missing PermissionMiddleware.
  2. Probe arbitrary directory existence: Send a crafted POST request to the download endpoint with a traversal identifier to check whether a target directory exists outside the plugin root:
    curl -X POST "http://<target>:9501/admin/plugin/store/download" \
      -H "Authorization: Bearer <token>" \
      -H "Content-Type: application/json" \
      -d '{"identifier": "../../etc", "version": "1.0.0"}'
    The server resolves this to BASE_PATH/plugin/../../etc, revealing directory existence via response differences.
  3. Trigger plugin install on an arbitrary path: Send a POST request to the install endpoint with a traversal identifier pointing to a target directory (e.g., the application root):
    curl -X POST "http://<target>:9501/admin/plugin/store/install" \
      -H "Authorization: Bearer <token>" \
      -H "Content-Type: application/json" \
      -d '{"identifier": "../app", "version": "1.0.0"}'
    This resolves to BASE_PATH/plugin/../app = BASE_PATH/app, causing Plugin::install("../app") to process the application directory as a plugin.
  4. Achieve code execution: If Plugin::install() runs Composer commands against the traversed directory, an attacker who can influence composer.json in that directory (or who targets a directory with a malicious composer.json) can achieve arbitrary code execution with the privileges of the web application process (GitHub Advisory, MineAdmin Security Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /admin/plugin/store/install, /admin/plugin/store/uninstall, or /admin/plugin/store/download containing ../ or URL-encoded traversal sequences (e.g., %2e%2e%2f) in the identifier JSON field.
  • Logs: Web server or application access logs showing requests to the above endpoints with identifier values containing path separators or traversal patterns; repeated requests from a single authenticated user probing different traversal depths.
  • File System: Unexpected install.lock files appearing outside the /plugin/ directory; new or modified files in application directories (e.g., BASE_PATH/app/) that correspond to plugin installation artifacts.
  • Process: Unexpected composer child processes spawned by the PHP/web application process, particularly targeting directories outside the designated plugin path.

Mitigation and workarounds

Upgrade to MineAdmin version 3.2.0-alpha.2 or later, which introduces a normalizeIdentifier() method that validates the identifier parameter against a strict allowlist regex (/\A[A-Za-z0-9_-]+\/[A-Za-z0-9_-]+\z/) before any file system operations, and adds PermissionMiddleware and a plugin:store permission check to the IndexController (MineAdmin Release, Patch Commit). As a temporary workaround for those unable to upgrade immediately, restrict access to the /admin/plugin/store/* endpoints at the network or reverse-proxy level to trusted administrator IP addresses only. Additionally, ensure that the application process runs with the minimum necessary file system privileges to limit the impact of any traversal exploitation.

Community reactions

A technical blog post covering CVE-2026-55224 alongside other unauthenticated infrastructure vulnerabilities was published by security researcher Deniz Halil on August 20, 2026, and referenced again in a broader roundup on August 24, 2026 (Deniz Halil Blog). The vulnerability was also picked up by Tenable's cloud security plugin catalog and by the ProjectDiscovery Nuclei templates project, indicating moderate community interest in detection coverage (Nuclei Templates).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-65954HIGH8.6
  • PHP logoPHP
  • composer://phpcsstandards/phpcsutils
NoYesSep 29, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb:11.8::mariadb-common
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management