CVE-2026-56704: Vrana Adminer
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.
Affected products
- Vrana Adminer: before 5.4.3 (fixed in 5.4.3)
Published 2026-08-25. Last modified 2026-09-08.