Remote Code Execution in Adminer SQLite Query Handling
CVE-2026-56703
8.6HIGH
What is CVE-2026-56703?
A vulnerability in Adminer before version 5.4.3 allows authenticated attackers to exploit weaknesses in SQLite query processing. Specifically, the VACUUM INTO command is not sufficiently restricted by ATTACH limitations, enabling malicious users to write PHP code to arbitrary file paths on the server and execute commands, potentially compromising the entire system.
Affected Version(s)
adminer 0 < 5.4.3
adminer 5.4.3
