CVE-2026-56705 (matched: php)

  • Tuesday, 25th August, 2026
  • 10:06am

A security flaw has been identified in versions of Adminer, a popular tool used to manage website databases, that are older than 5.4.3. The issue occurs because the tool does not properly clean input entered in its server connection field, allowing unauthenticated attackers to inject harmful database configuration settings by adding semicolons to their input.

If successfully exploited, attackers can use these injected settings to write malicious code directly to your website’s public file directory. When that malicious file is accessed, the attacker can run arbitrary commands on your site, which may lead to stolen customer data, full hijacking of your website, or other harmful activity.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-56705

« Back