← Terug naar overzicht

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin. Authenticated users can exploit a permissive default extension allowlist to upload PHP files, including webshells. The attack targets database columns ending in '_path' and requires the uploadPath directory to be web-served. Successful exploitation allows arbitrary code execution as the web-server user. The vulnerability is tracked as CVE-2026-56702 and has been patched in version 5.4.3. A GitHub security advisory and VulnCheck advisory have been published detailing the issue. The risk is rated High due to the potential for full server compromise post-authentication.

Affected products

  • Adminer
  • AdminerFileUpload plugin

Related CVE's

  • CVE-2026-56702

Categories

  • Database & Storage
  • Web Technologies