CVE-2026-56705 (matched: php)

  • Tuesday, 25th August, 2026
  • 16:06pm

A security vulnerability has been identified in Adminer, a common tool used to manage website databases, that impacts all versions released before 5.4.3. The flaw allows unauthenticated attackers (people who do not have login credentials for your site or Adminer) to inject extra commands when setting up a database connection. Attackers can exploit this to write malicious PHP code directly to your website's public files. If that malicious file is accessed, the attacker can run arbitrary code on your hosting account, which may be used to steal data, modify your site's content, or perform other unauthorized actions.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-56705

« Back