Executive brief
Adminer is a database management tool used to administer databases via a web interface. Authenticated attackers can exploit a vulnerability in SQLite query handling to write arbitrary PHP code to the web server and execute system commands, gaining full control of the server.
Technical details
The vulnerability is a code injection flaw (CWE-94) caused by an incomplete blocklist (CWE-184) in SQLite query restrictions. Adminer blocks the ATTACH command to prevent arbitrary file creation, but fails to restrict the VACUUM INTO command, which can write a database file containing attacker-controlled PHP code to any path with any extension. An authenticated SQLite user can craft a CREATE TABLE statement with embedded PHP code, then use VACUUM INTO to write the database to the web root as a .php file, which is then executed by the PHP interpreter. The attack requires network access to Adminer and valid SQLite authentication credentials, but no user interaction. The vulnerability was patched in version 5.4.3.
Affected products
- Adminer Adminer before 5.4.3
Timeline
- 2026-07-09: disclosed
- 2026-08-25: advisory
- 2026-08-25: patched: Version 5.4.3 released