PT-2026-81132 · Adminer · Adminer

·

CVE-2026-56705

·

Published

2026-07-09

·

Updated

2026-08-25

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adminer versions prior to 5.4.3
Description Insufficient sanitization of the server field during the construction of a PDO DSN (Data Source Name) string allows unauthenticated attackers to inject ODBC parameters using semicolons. By injecting the TraceFile and TraceOn parameters, an attacker can write PHP code directly into the web root, leading to remote code execution when the resulting trace file is accessed.
Recommendations Update to version 5.4.3 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12785
CVE-2026-56705
GHSA-R4X9-5M63-3VXW

Affected Products

Adminer