PatchSiren

vrana CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vrana CVE published 2026-08-25

CVE-2026-56706

Adminer before 5.4.3 has a CSRF token scheme vulnerability. The implementation transmits both the XOR mask and the masked value in every token, allowing an attacker to recover the session secret with a single XOR operation and forge unlimited valid tokens. The low-entropy session token and loose comparison in token verification further weaken the implementation. This vulnerability enables cross-site reque [truncated]

CRITICAL vrana CVE published 2026-08-25

CVE-2026-56705

CVE-2026-56705 is a critical vulnerability in Adminer that allows unauthenticated attackers to inject ODBC parameters via semicolons, potentially leading to remote code execution when the trace file is accessed. The vulnerability affects Adminer versions before 5.4.3 and involves the failure to sanitize the server field before constructing a PDO DSN string. Defenders should prioritize verifying Adminer ve [truncated]

MEDIUM vrana CVE published 2026-08-25

CVE-2026-56704

CVE-2026-56704 is a medium-severity vulnerability in Adminer, a database management tool, that allows attackers controlling a rogue MySQL server to execute arbitrary JavaScript code by returning crafted version strings. This bypasses Content Security Policy (CSP) protections. Defenders should assess exposure, prioritize remediation, and verify inventory for potential impact.

HIGH vrana CVE published 2026-08-25

CVE-2026-56703

CVE-2026-56703 is a high-severity vulnerability in Adminer, a database management tool, which allows authenticated attackers to execute remote code via SQLite query handling. The vulnerability arises from the lack of blocking for VACUUM INTO despite ATTACH restrictions, enabling attackers to write PHP code to arbitrary file paths and execute commands on the server. Defenders should assess exposure, priori [truncated]

HIGH vrana CVE published 2026-08-25

CVE-2026-56702

CVE-2026-56702 debrief based on the supplied source corpus. The vulnerability is an unrestricted file upload issue in the AdminerFileUpload plugin of Adminer versions before 5.4.3. Authenticated users can exploit a permissive default extension allowlist to upload PHP files, potentially leading to arbitrary code execution as the web-server user when the uploadPath is web-served. Defenders should assess exp [truncated]

HIGH vrana CVE published 2026-08-25

CVE-2026-34968

CVE-2026-34968 is an arbitrary file deletion vulnerability in Adminer before version 5.4.3, specifically in SQLite mode. An authenticated attacker can delete arbitrary files writable by the PHP process by submitting relative file paths in the db[] parameter during the database-list drop action. This vulnerability allows attackers to potentially delete critical files, leading to service disruption or data [truncated]

MEDIUM vrana CVE published 2026-08-25

CVE-2026-34967

CVE-2026-34967 debrief based on the supplied source corpus. The vulnerability is an arbitrary file write issue in Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable directory on the host. This issue has a medium severity and defende [truncated]

MEDIUM vrana CVE published 2026-08-25

CVE-2026-34964

CVE-2026-34964 is a server-side request forgery vulnerability in Adminer before 5.5.0. The login form's server field validator only checks leading integers for privileged ports and does not reject non-numeric port values. This allows attackers to inject PDO DSN keys like host= and port= into the server parameter, bypassing the privileged-port restriction and establishing TCP connections to arbitrary inter [truncated]

MEDIUM vrana CVE published 2026-08-25

CVE-2026-34959

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER[REQUEST_URI] with no trusted-proxy check and no validation of the prefix value. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links. The vulnerability has a CVSS score of 5.3 and a severity of [truncated]

LOW vrana CVE published 2026-08-25

CVE-2026-16434

CVE-2026-16434 is a vulnerability in Adminer versions 4.6.0 through 5.5.0, which was fixed in version 5.5.1. The issue is an incomplete fix for a prior X-Forwarded-Prefix vulnerability. The validation guard in bootstrap.inc.php only rejects prefixes matching ^/[^/], which allows certain malicious prefixes to bypass validation. This can lead to anomalous cookie-path scoping. The vulnerability requires that [truncated]