CVE-2026-56703

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-25 02:16

Updated : 2026-09-08 20:23


NVD link : CVE-2026-56703

Mitre link : CVE-2026-56703

CVE.ORG link : CVE-2026-56703


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')