CVE-2026-56705 CRITICAL

CVE-2026-56705: Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection

Vendor Vrana
Product adminer
Weakness CWE-73
Published August 25, 2026
Last update August 25, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 25, 2026 Record updated

Related vulnerabilities

04Related CVE