CVE-2026-56702: Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in path and execute arbitrary code as the web-server user when uploadPath is web-served.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adminerto a version that resolves this vulnerability.Fixed in 5.4.3 - Configuration
Remove/deny PHP from the AdminerFileUpload plugin’s default extension allowlist so uploaded files cannot be PHP webshells.
AdminerFileUpload plugin default extension allowlist (permissive) = tighten to disallow PHP (e.g., remove/deny .php uploads) - Compensating control
Ensure AdminerFileUpload uploadPath is not web-served (do not allow uploaded files to be reachable via the web server); prevent execution by keeping uploaded files outside the document root or otherwise blocking direct web access.
Event History
Frequently Asked Questions
Which deployments are exposed to code execution?
Deployments using the AdminerFileUpload plugin are exposed when an authenticated user can upload to a column whose name ends in _path and uploadPath is served by the web server. In that configuration, an uploaded PHP file can be executed as the web-server user.
Does exploitation require authentication or user interaction?
An attacker needs authentication with access to perform the relevant upload. No user interaction is required, and the attack can be performed remotely.
Are default plugin settings affected?
Yes. The issue relies on a permissive default extension allowlist in the AdminerFileUpload plugin, which permits PHP file uploads.
What can be done while an update is pending?
Ensure uploadPath is not web-served, which prevents uploaded PHP files from being executed through the web server. Restricting access to the affected upload functionality also limits who can exploit it.