Remote Code Execution Vulnerability in Adminer by VRana
CVE-2026-56705

9.3CRITICAL

Key Information:

Vendor

Vrana

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-56705?

The Adminer tool by VRana, prior to version 5.4.3, contains a flaw in the handling of the server field when constructing a PDO DSN string. This inadequacy allows unauthenticated attackers to inject ODBC parameters through semicolons. By manipulating parameters like TraceFile and TraceOn, malicious actors can potentially write arbitrary PHP code to the web root. This opens up a pathway for remote code execution whenever the crafted trace file is accessed, exposing users to significant security risks.

Affected Version(s)

adminer 0 < 5.4.3

adminer 5.4.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AmirMSafari
.