CVE-2026-56704 MEDIUM

CVE-2026-56704: Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String

Vendor Vrana
Product adminer
Weakness CWE-79 · XSS
Published August 25, 2026
Last update August 25, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.

Key dates

02Disclosure timeline

August 25, 2026 CVE published

Related vulnerabilities

04Related CVE