Junglewise Threat Intelligence

CVE-2026-56704: Adminer cross-site scripting via MySQL version string

CVE-2026-56704 · Severity: medium · CVSS 6.1 · Published 2026-08-25

Technologies: Adminer. Vendors: Adminer.

Executive brief

Adminer is a popular web-based database management tool that allows administrators to manage databases through a browser interface. The application fails to properly sanitize database server version strings before inserting them into JavaScript code, allowing an attacker controlling a rogue MySQL server to inject malicious JavaScript that executes with full privileges despite Content Security Policy protections. This can lead to account compromise, credential theft, or arbitrary actions performed on the database.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in adminer.inc.php line 1081, where the database server version string is inserted directly into a script tag with a valid CSP nonce without sanitization. The vulnerable code uses preg_replace with an insufficient regex pattern that fails to match version strings not starting with digit+dot+digit, causing the original unsanitized string to be returned. An attacker controlling a reachable MySQL server can return a crafted version string (e.g., "1');alert(origin)//") that breaks out of the JavaScript context and executes arbitrary code. The nonce on the script tag bypasses Content Security Policy protections. No authentication is required if combined with login CSRF, as the login form lacks CSRF tokens. The fix is available in version 5.4.3.

Affected products

  • Adminer Adminer before 5.4.3

Timeline

  • 2026-07-09: disclosed: GitHub security advisory published
  • 2026-08-25: disclosed: CVE-2026-56704 published
  • 2026-07-09: patched: Version 5.4.3 released with fix

References

Related threats