Executive brief
Adminer is a web-based database management tool used to administer databases like SQLite, MySQL, and PostgreSQL. This vulnerability allows authenticated users to upload a malicious SQL file through the import feature that, when processed, creates PHP files executable by the web server, leading to complete code execution. An attacker with database access credentials can use this to establish persistent access to the underlying web server and compromise the entire system.
Technical details
This is a patch bypass vulnerability (CVE-2026-15686) that exploits catastrophic backtracking in a regular expression designed to block SQLite ATTACH statements. The vulnerable code in sql.inc.php uses a possessive quantifier (*+) in the regex filter that, when processing a SQL file containing approximately 350,000 SQLite comment lines (--), causes PHP's preg_match() function to hit its backtracking limit and return false instead of 0 or 1. The code incorrectly treats false as equivalent to "no match," allowing the malicious ATTACH statement to bypass the security filter. An authenticated attacker can exploit this during the SQL import process by uploading a crafted SQL file that creates a .php file with embedded PHP code. The vulnerability is present in Adminer 5.4.2 and was patched in 5.4.3. Authentication to the database is required, but this is often the default password or publicly known credentials in development environments.
Affected products
- Adminer Adminer 5.4.2
Timeline
- 2026-03-06: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: Coordinated public release of advisory; Adminer 5.4.3 issued with patch
- 2026-07-29: advisory: ZDI-26-478 published
- 2026-08-20: other: CVE-2026-15686 published