GHSA-f339-246p-wwjp
FroshAdminer Adminer UI is accessible without admin session
Quick fix
GHSA-f339-246p-wwjp — frosh/adminer-platform: upgrade to the fixed version with the command below.
composer require frosh/adminer-platform:^2.2.1Details
### Summary Unauthenticated access to Adminer UI
### Details The Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users.
Note: Database access itself requires credentials that are only set through the ACL-protected API endpoint. Direct database access without prior admin login is not possible through this vulnerability alone.
### Impact An unauthenticated user could access the Adminer interface, potentially disclosing version information or exploiting Adminer-specific vulnerabilities.
### Patches Version 2.2.1 adds session validation. The Adminer route now verifies an authenticated session flag before rendering — returning HTTP 403 otherwise.
### Workarounds Deactivate or uninstall the plugin.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.2.1composer require frosh/adminer-platform:^2.2.1References
- https://github.com/FriendsOfShopware/FroshPlatformAdminer/security/advisories/GHSA-f339-246p-wwjp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25878[ADVISORY]
- https://github.com/FriendsOfShopware/FroshPlatformAdminer/commit/c4dd6c3462af178b3a7d146d3c651c2c253e902b[WEB]
- https://github.com/FriendsOfShopware/FroshPlatformAdminer[PACKAGE]
- https://github.com/FriendsOfShopware/FroshPlatformAdminer/releases/tag/2.2.1[WEB]