CVE-2026-56705 affects vrana/adminer versions before 5.4.3 and permits unauthenticated remote code execution through the MSSQL connection workflow. Insufficient sanitization of the server field lets an attacker inject ODBC parameters into the PDO DSN using semicolons; the issue carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and is categorized as CWE-73.
An attacker can set the ODBC TraceFile and TraceOn options to place PHP content in a web-accessible directory, then request the generated trace file to execute code on the server. A Nuclei proof-of-concept template reportedly validated exploitation against a vulnerable local Adminer instance and did not trigger against version 5.4.3. Organizations exposing Adminer with MSSQL support should upgrade to 5.4.3 or later and investigate web roots for unexpected trace or PHP files.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A Nuclei template demonstrated exploitation through Adminer's MSSQL authentication flow by writing pwn56705.php to candidate web roots and requesting it to confirm execution. It produced critical findings against a vulnerable local instance, including root-context execution, while a local Adminer 5.4.3 instance produced no findings.
CVE-2026-56705 was received by disclosure@vulncheck.com for an unauthenticated remote code execution flaw affecting Vrana Adminer versions before 5.4.3. The flaw permits MSSQL PDO DSN parameter injection through the server field, enabling TraceFile and TraceOn abuse to write PHP code into a web-accessible location.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.