Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin. Authenticated users can exploit a permissive default extension allowlist to upload PHP files, including webshells. The attack targets database columns ending in '_path' and requires the uploadPath directory to be web-served. Successful exploitation allows arbitrary code execution as the web-server user. The vulnerability is tracked as CVE-2026-56702 and has been patched in version 5.4.3. A GitHub security advisory and VulnCheck advisory have been published detailing the issue. The risk is rated High due to the potential for full server compromise post-authentication.