CVE-2026-56703
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| vrana | adminer | 0 < 5.4.3 | affected |
| vrana | adminer | 5.4.3 | unaffected |
Weaknesses
- CWE-94: Improper Control of Generation of Code ('Code Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
- https://github.com/vrana/adminer/security/advisories/GHSA-gmx3-g29w-77wf
- https://www.vulncheck.com/advisories/adminer-before-remote-code-execution-via-sqlite-vacuum-into
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.