Vulnerability Description
Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/vrana/adminer/security/advisories/GHSA-h6jr-7pr6-grgj
- https://www.vulncheck.com/advisories/adminer-before-cross-site-scripting-via-mys
FAQ
What is CVE-2026-56704?
CVE-2026-56704 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted...
How severe is CVE-2026-56704?
CVE-2026-56704 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56704?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.