Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method. The issue results from an incorrect check of a function return value. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-28201.
History

Thu, 20 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Adminer
Adminer adminer
Vendors & Products Adminer
Adminer adminer

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method. The issue results from an incorrect check of a function return value. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-28201.
Title Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
Weaknesses CWE-253
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:25:10.407Z

Reserved: 2026-07-13T21:31:19.881Z

Link: CVE-2026-15686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:21.180

Modified: 2026-08-20T17:17:21.180

Link: CVE-2026-15686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:30:03Z