CRITICAL 9.8 CVE-2026-56705 Published 25 Aug 2026

Adminer RCE via Unsanitized Server Field

Worried this affects one of your servers?

Adminer, a lightweight database management tool, is affected by a remote code execution (RCE) vulnerability in versions before 5.4.3.

Due to insufficient sanitization of the 'server' field, unauthenticated attackers can inject ODBC parameters via semicolons, allowing them to write PHP code to the web root.

This vulnerability can be exploited when the trace file is accessed, leading to remote code execution.

Reference: CVE-2026-56705 on NVD

← Back to Security News