PT-2026-81126 · Adminer · Adminer

·

CVE-2026-34964

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Adminer versions prior to 5.5.0
Description A server-side request forgery (SSRF) issue exists in the login form's server field validator. The validator only checks leading integers for privileged ports and does not reject non-numeric port values. This allows attackers to inject PDO DSN keys, such as host= and port=, into the server parameter to bypass restrictions on privileged ports and establish TCP connections to arbitrary internal hosts and ports before authentication.
Recommendations Update to version 5.5.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34964
GHSA-58CQ-MGW2-38M5

Affected Products

Adminer