Arbitrary File Write Vulnerability in Adminer SQL-Log Plugin by Adminer
CVE-2026-34967
5.3MEDIUM
What is CVE-2026-34967?
An arbitrary file write vulnerability exists in Adminer versions 5.3.0 through 5.4.2 when the sql-log plugin is enabled. This vulnerability allows an authenticated user to exploit the 'ns' parameter in plugins/sql-log.php. By supplying path traversal sequences, the attacker can manipulate the system to write arbitrary .sql files with unauthorized content to any writable directory on the host. This could potentially lead to unauthorized data access or manipulation, highlighting the critical need for immediate action to secure affected installations.
Affected Version(s)
adminer 0
