CVE-2026-56705 is an unauthenticated remote code execution vulnerability in Adminer versions before 5.4.3. Adminer fails to sanitize the MSSQL server field before incorporating it into a PDO DSN. An attacker can use semicolon-delimited input to inject ODBC connection parameters, including tracing options that direct trace output to an attacker-selected web-accessible location. If the generated trace content is interpreted by the web server as PHP, requesting the trace file executes attacker-controlled code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a README and one Python 3 executable, adminer_exploit.py. It is a standalone, interactive mass-exploitation utility rather than a Metasploit/Nuclei-style module. The operator supplies a text file of target hosts; the script normalizes and de-duplicates entries, clears Pwned.txt, and processes targets with up to 120 concurrent workers. For each host it performs broad HTTP Adminer discovery using common paths, robots.txt, sitemap files, lightweight link crawling, directory/name fuzzing, and version-specific Adminer filenames. Candidate pages are identified by an Adminer auth[driver] login-form field and optionally version-checked; versions 5.4.3 and later are skipped when detectable. The exploitation routine POSTs to a discovered Adminer page with ext=pdo and auth[driver]=mssql. It injects a TraceFile/TraceOn sequence into auth[server] while placing a hard-coded PHP webshell in auth[username], then checks for a generated .php file adjacent to Adminer. A verified shell URL is saved locally. The payload is operational but hard-coded: it provides host disclosure and unauthenticated file upload, with generated filenames used only for the deployed shell. No fixed victim domain, external command-and-control endpoint, or exfiltration destination is present; network destinations are entirely derived from the target list. The claimed exploitability and exact DSN/trace-file behavior are not independently established by this repository, but the code's stated vulnerability path and implemented behavior are consistent with an attempted RCE exploit rather than a detection-only script.
This six-file repository contains an operational Python exploit (poc.py), a Nuclei verification/exploitation template (CVE-2026-56705.yaml), documentation, and a Docker lab recipe. It targets an unauthenticated MSSQL PDO DSN injection in Adminer versions before 5.4.3. The attacker submits a server value containing semicolon-delimited ODBC attributes, specifically TraceFile and TraceOn, and places PHP in the username. The claimed behavior is that ODBC writes connection trace data—including the unescaped username—to the selected trace file before a database connection fails. If that file is under a writable web root, requesting it executes the embedded PHP. poc.py first fingerprints an Adminer version, aborts for 5.4.3 or newer, generates a random PHP filename and marker, POSTs the injection, then GETs the resulting shell with a configurable command (default: id). The Nuclei template performs analogous requests, captures adminer_sid from the login response, tries three common web-root paths, and matches RCE56705OK. The lab Dockerfile provisions PHP 8.3, pdo_sqlsrv, unixODBC, and Microsoft ODBC Driver 18, then serves Adminer from /var/www on port 8081. Documentation describes successful root-level command execution in the lab and mitigation by upgrading Adminer or disabling/filtering the MSSQL path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Adminer before version 5.4.3 caused by improper sanitization of the server field when constructing a PDO DSN string, enabling unauthenticated ODBC parameter injection and PHP code write to the web root.
An unauthenticated remote-code-execution vulnerability in Adminer versions earlier than 5.4.3. The flaw uses injection into an MSSQL PDO DSN's server parameter to enable SQL Server tracing and write a PHP payload into a web-accessible directory, enabling execution as the web-server process (demonstrated as root in the test environment).
An unpatched, critical network-accessible vulnerability tracked as CVE-2026-56705, affecting Debian Linux 11.0, 12.0, and 13.0 and associated with the Adminer package CPE. The supplied CVSS v3.0 vector indicates unauthenticated remote exploitation with high confidentiality, integrity, and availability impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.