Arbitrary File Write Vulnerability in Adminer SQL-Log Plugin by Adminer
CVE-2026-34967

5.3MEDIUM

Key Information:

Vendor

Vrana

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-34967?

An arbitrary file write vulnerability exists in Adminer versions 5.3.0 through 5.4.2 when the sql-log plugin is enabled. This vulnerability allows an authenticated user to exploit the 'ns' parameter in plugins/sql-log.php. By supplying path traversal sequences, the attacker can manipulate the system to write arbitrary .sql files with unauthorized content to any writable directory on the host. This could potentially lead to unauthorized data access or manipulation, highlighting the critical need for immediate action to secure affected installations.

Affected Version(s)

adminer 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kah-ja
.