Threat intelligence dashboard
CVE-2026-100695medium

Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE

Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database has FILE privileges and can write to the webroot, attackers can use the XSS to submit authenticated SQL requests that write PHP files via INTO DUMPFILE, achieving remote code execution as the web server account.

Risk score

5.3

CVSS 4.0

Vendor
vrana
Product
adminer
CWE
CWE-79
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

adminer

vrana

Version / rangeStatusType
0 to before 6.0.2affectedsemver
6.0.2unaffectedsemver

Technical metrics

5.3

CVSS 4.0

Severity
medium
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

6.1

CVSS 3.1

Severity
medium
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N