CVE-2026-25892General(adminer / adminer)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker can POST version[] parameter which PHP converts to an array. On next page load, openssl_verify() receives this array instead of string and throws TypeError, returning HTTP 500 to all users. Upgrade to Adminer 5.4.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adminer

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-11)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
adminer

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-03-11: 3Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-03-11: 202-0902-1003-11
Signal classification2 categories
General
466.7%
Disclosure
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure1General1
2026-03-113
General3
Full discourse6 posts
  • Petr Safarcik@psafarcik_
    General

    Je to jedna z možností, každopádně to byl útok RCE, a buď se využila Adminer CVE-2026-25892, nebo nějaký jiný útok skrz např. nahrání souboru přes form, etc., a pak se Adminer využil při remote shellu, není v tom úplně jasno. Každopádně je to nešťastné, Adminer by určitě neměl být public, ani v perimetru. Nicméně není to tak úplně neobvyklé, dají se najít public instance Admineru (většina z nich má aspoň chráněný access) https://x.com/psafarcik_/status/2031640456287723733

    Post summary

    The post references a potential RCE via Adminer CVE‑2026‑25892 but provides no proof of exploit, active use, or remediation information.

    10020954
    578 followersView on X
  • Petr Safarcik@psafarcik_
    General

    @divispetr @chupascz @Slavia_poj Vůbec ne, i kdyby útok byl přímo proveden přes CVE-2026-25892 (možná byl ale stejně proveden přes jiné RCE), tak je to chyba výhradně admina, že dovolí public access, a navíc neaktualizují.

    Post summary

    The comment references CVE‑2026‑25892, noting it is an RCE, but provides no proof of exploitation, tool, patch, or False‑Positive claim.

    1001086
    578 followersView on X
  • Petr Safarcik@psafarcik_
    General

    @BajzathJakub Zdravím na Slovensko, minimálně pro případ CVE-2026-25892 to vypadá, že SK public IPs jsou safe. https://x.com/psafarcik_/status/2031640456287723733?s=20

    Post summary

    The tweet simply reassures that Slovak public IPs seem safe for CVE‑2026‑25892, offering no additional technical or exploit details.

    00010106
    578 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25892 Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where http://adminer.org sends signed version info via JavaScri… https://www.cve.org/CVERecord?id=CVE-2026-25892

    Post summary

    The post briefly highlights a flaw in Adminer v5.4.1 and earlier involving a signed version-check mechanism sent via JavaScript, but offers no exploitation or patch details.

    00010209
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25892 Adminer Version Disclosure Vulnerability via Unauthenticated POST Request https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25892

    Post summary

    The text announces CVE-2026-25892 as an Adminer version disclosure flaw exploitable via unauthenticated POST requests, but it offers no evidence of exploits, patches, or active attacks.

    0000066
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25892: Adminer CVE-2026-25892: The Self-Destructing Version Check Adminer, the popular single-file database management tool, contains a logic flaw in its update mechanism that allows unauthenticated attackers to persistently brick the applica... https://cvereports.com/reports/CVE-2026-25892

    Post summary

    Adminer’s update mechanism has a logic flaw that lets unauthenticated attackers persistently brick the application.

    0000047
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadmineradminer---

Explore more