CVE-2026-56704: Vrana Adminer

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.

Affected products

  • Vrana Adminer: before 5.4.3 (fixed in 5.4.3)

Published 2026-08-25. Last modified 2026-09-08.