Remote Code Execution in Adminer Due to Function Mischeck
CVE-2026-15686

7.2HIGH

Key Information:

Vendor

Adminer

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-15686?

A vulnerability in the multi_query method of Adminer has been identified, where an improper check of a function's return value can be exploited by authenticated attackers to execute arbitrary code on the server. This critical flaw poses significant risks, as it allows attackers to manipulate the execution flow and potentially access sensitive data or services. Safeguarding your installations with the latest updates is essential to mitigate the risks associated with this issue.

Affected Version(s)

Adminer 5.4.2

References

CVSS V3.0

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.