CVE-2026-56705

Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.


We have discovered 271 live websites that are affected by CVE-2026-56705.

Run a Free Instant Scan




Affected Software

Product  Adminer
Category Database Managers
Vulnerable Domains271 live websites (100% of Adminer install base)
Vulnerable Versions
  • from 0 through 5.4.3
Vulnerable Versions Count16 versions ( 89% of all versions)



Details

  • Published - Aug 25, 2026
  • Updated - Aug 25, 2026

Credits

  • AmirMSafari (reporter)

Website Distribution by Country

Number of websites using CVE-2026-56705
United States43 websites



Czech Republic87 websites
Germany55 websites
France26 websites
Slovakia9 websites
Sweden7 websites
Belgium6 websites
Australia4 websites
China4 websites
Spain4 websites

Website Distribution by TLD

Number of websites using CVE-2026-56705
.cz83 websites
.com61 websites
.de24 websites
.net19 websites
.eu14 websites
.fr8 websites
.se6 websites
.be5 websites
.ch5 websites
.ru4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-56705

Top websites that are affected by CVE-2026-56705. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.********.com Czech Republic**,***
*******.*****.cz Czech Republic***,***
******.*************.cz Czech Republic***,***
*******.***.cn China***,***
***.*******.net Poland*,***,***
***.*************.de Germany*,***,***
****.********.net United States*,***,***
********.cz Germany*,***,***
***.**************.de Germany*,***,***
*****************.*******************.de Germany*,***,***
See full domain list

FAQ

A total of 271 websites have been identified as vulnerable to CVE-2026-56705, based on global website indexing conducted by WebTechSurvey.
The Adminer is affected by the CVE-2026-56705 vulnerability.
Adminer versions up to 5.4.3 are vulnerable to CVE-2026-56705.
CVE-2026-56705 is resolved in version 5.4.3 of Adminer.