Unrestricted File Upload Vulnerability in Adminer by Adminer
CVE-2026-56702
7.1HIGH
What is CVE-2026-56702?
In Adminer versions prior to 5.4.3, the AdminerFileUpload plugin is susceptible to an unrestricted file upload flaw. This issue enables authenticated users to upload malicious PHP files by exploiting a permissive default extension allowlist. When the upload path is web-accessible, this vulnerability permits attackers to upload PHP webshells and execute arbitrary code with the same privileges as the web server user, potentially compromising the entire environment.
Affected Version(s)
adminer 0 < 5.4.3
adminer 5.4.3
