ZDI-CAN-28201: ZDI-26-478: Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multiquery method. The issue results from an incorrect check of a function return value. An attacker can leverage this vulnerability to execute code in the context of the web server.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-15686.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adminerto a version that resolves this vulnerability.Patch ZDI-26-478 - Compensating control
Because the vulnerability allows remote attackers to execute arbitrary code and requires authentication to exploit, restrict access to the Adminer web interface to only trusted users/clients (e.g., limit by IP at a firewall/reverse proxy) to reduce the chance that authenticated attackers can reach it.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this vulnerability?
An attacker must authenticate to the affected Adminer installation before exploiting the issue. The provided information does not identify which authenticated roles or privileges are sufficient.
What is the potential impact after successful exploitation?
The issue can allow an authenticated remote attacker to execute arbitrary code on an affected Adminer installation. The provided information does not state whether any default configuration is affected or which versions are vulnerable.