CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56703

highCVSS 7.2covered by 1 sourcefirst seen 2026-08-25
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.

⚡ Watch CVE-2026-56703

Get an email if CVE-2026-56703 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-56703

CVE.org record

Embed the live status

CVE-2026-56703 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56703 status](https://www.csirts.com/badge/CVE-2026-56703)](https://www.csirts.com/cve/CVE-2026-56703)