CVE-2026-34968: Vrana Adminer

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any files writable by the PHP process.

Affected products

  • Vrana Adminer: before 5.4.3 (fixed in 5.4.3)

Published 2026-08-25. Last modified 2026-09-08.