PatchSiren

Adminer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Adminer CVE published 2026-08-20

CVE-2026-15686

The CVE-2026-15686 vulnerability is an incorrect check of a function return value in the multi_query method of Adminer, allowing remote attackers to execute arbitrary code on affected installations. This requires authentication to exploit. Adminer users, administrators, and security teams should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability has a CVSS score of [truncated]

Known exploited Adminer CVE published 2025-09-29

CVE-2021-21311

CVE-2021-21311 is a Server-Side Request Forgery (SSRF) vulnerability in Adminer. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2025-09-29, which indicates known exploitation and a need for urgent remediation planning. Organizations that use Adminer should treat this as a high-priority exposure, especially if the service is reachable from untrusted networks.