Sploitus

CVE-2026-56705

5 known exploits for CVE-2026-56705

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.

Affected products
Adminer
CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (40th percentile)
Weakness
CWE-73
NVD status
Received
Published
2026-08-25
CVE-2026-56705 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2026-56705

Proof-of-concept code and exploit modules indexed by Sploitus