PT-2026-7169 · Adminer · Adminer

Joyghoshs

·

Published

2026-02-09

·

Updated

2026-02-10

·

CVE-2026-25892

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Adminer versions prior to 5.4.2
Description Adminer is database management software. Versions 5.4.1 and earlier have a flawed version check process. The adminer.org domain sends signed version information via JavaScript postMessage, which is then sent by the browser to the ''?script=version'' endpoint. This endpoint does not validate the origin of the POST request, allowing attackers to send a crafted version[] parameter. PHP interprets this parameter as an array, which causes a TypeError when passed to the openssl verify() function, resulting in an HTTP 500 error for all users.
Recommendations Upgrade to Adminer version 5.4.2.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-25892
GHSA-Q4F2-39GR-45JH

Affected Products

Adminer