Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port= into the server parameter to bypass the privileged-port restriction and establish TCP connections to arbitrary internal hosts and ports before authentication.
We have discovered 274 live websites that are affected by CVE-2026-34964.
| Product | |
| Category | Database Managers |
| Vulnerable Domains | 274 live websites (100% of Adminer install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 17 versions ( 94% of all versions) |
| 44 websites | |
| 87 websites | |
| 55 websites | |
| 26 websites | |
| 9 websites | |
| 9 websites | |
| 6 websites | |
| 4 websites | |
| 4 websites | |
| 4 websites |
| .cz | 83 websites |
| .com | 62 websites |
| .de | 24 websites |
| .net | 19 websites |
| .eu | 14 websites |
| .fr | 8 websites |
| .se | 7 websites |
| .be | 5 websites |
| .ch | 5 websites |
| .ru | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.********.com | **,*** | ||
| *******.*****.cz | ***,*** | ||
| ******.*************.cz | ***,*** | ||
| *******.***.cn | ***,*** | ||
| ***.*******.net | *,***,*** | ||
| ***.*************.de | *,***,*** | ||
| ****.********.net | *,***,*** | ||
| ********.cz | *,***,*** | ||
| ***.**************.de | *,***,*** | ||
| *****************.*******************.de | *,***,*** |
FAQ