Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vrana
Vrana adminer |
|
| Vendors & Products |
Vrana
Vrana adminer |
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port= into the server parameter to bypass the privileged-port restriction and establish TCP connections to arbitrary internal hosts and ports before authentication. | |
| Title | Adminer before 5.5.0 SSRF via PDO DSN Injection | |
| First Time appeared |
Adminer
Adminer adminer |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:adminer:adminer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Adminer
Adminer adminer |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:29:58.396Z
Reserved: 2026-03-31T17:58:43.754Z
Link: CVE-2026-34964
No data.
Status : Received
Published: 2026-08-25T02:16:40.553
Modified: 2026-08-25T02:16:40.553
Link: CVE-2026-34964
No data.
OpenCVE Enrichment
Updated: 2026-08-25T04:00:08Z