PT-2026-81127 · Adminer · Adminer

·

CVE-2026-34967

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Adminer versions 5.3.0 through 5.4.2
Description An arbitrary file write issue exists when the sql-log plugin is enabled. An authenticated user can utilize path traversal sequences—a technique used to access files and directories outside the intended folder—via the ns parameter in the 'plugins/sql-log.php' endpoint to write arbitrary .sql files with controlled content to any writable directory on the host.
Recommendations Update Adminer to a version later than 5.4.2. As a temporary mitigation, disable the sql-log plugin or restrict access to the ns parameter in the 'plugins/sql-log.php' endpoint.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34967
GHSA-75XM-QWFQ-9WP5

Affected Products

Adminer