Remote Code Execution Vulnerability in Adminer by VRana
CVE-2026-56705
9.3CRITICAL
What is CVE-2026-56705?
The Adminer tool by VRana, prior to version 5.4.3, contains a flaw in the handling of the server field when constructing a PDO DSN string. This inadequacy allows unauthenticated attackers to inject ODBC parameters through semicolons. By manipulating parameters like TraceFile and TraceOn, malicious actors can potentially write arbitrary PHP code to the web root. This opens up a pathway for remote code execution whenever the crafted trace file is accessed, exposing users to significant security risks.
Affected Version(s)
adminer 0 < 5.4.3
adminer 5.4.3
