CVE-2026-100695: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vrana adminer
Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database has FILE privileges and can write to the webroot, attackers can use the XSS to submit authenticated SQL requests that write PHP files via INTO DUMPFILE, achieving remote code execution as the web server account.
AI Analysis
Technical Summary
CVE-2026-100695 is a cross-site scripting vulnerability in Adminer prior to version 6.0.2. The vulnerability arises because the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, enabling a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In scenarios where the database user has FILE privileges and can write to the webroot, attackers can exploit this XSS to perform authenticated SQL queries that write PHP files using INTO DUMPFILE, resulting in remote code execution under the web server account.
Potential Impact
This vulnerability allows attackers to execute arbitrary JavaScript within the authenticated Adminer session, which can lead to session hijacking or other client-side attacks. More critically, in environments where the database has FILE privileges and can write to the webroot, attackers can escalate this to remote code execution by writing PHP files via SQL commands, compromising the server with the web server's privileges.
Mitigation Recommendations
Adminer version 6.0.2 or later addresses this vulnerability. Users should upgrade to Adminer 6.0.2 or newer to remediate this issue. No other mitigations are specified in the provided data.
CVE-2026-100695: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vrana adminer
Description
Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database has FILE privileges and can write to the webroot, attackers can use the XSS to submit authenticated SQL requests that write PHP files via INTO DUMPFILE, achieving remote code execution as the web server account.
CVSS v4.0
Score 5.3medium
Affected software
vrana
adminer
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100695 is a cross-site scripting vulnerability in Adminer prior to version 6.0.2. The vulnerability arises because the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, enabling a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In scenarios where the database user has FILE privileges and can write to the webroot, attackers can exploit this XSS to perform authenticated SQL queries that write PHP files using INTO DUMPFILE, resulting in remote code execution under the web server account.
Potential Impact
This vulnerability allows attackers to execute arbitrary JavaScript within the authenticated Adminer session, which can lead to session hijacking or other client-side attacks. More critically, in environments where the database has FILE privileges and can write to the webroot, attackers can escalate this to remote code execution by writing PHP files via SQL commands, compromising the server with the web server's privileges.
Mitigation Recommendations
Adminer version 6.0.2 or later addresses this vulnerability. Users should upgrade to Adminer 6.0.2 or newer to remediate this issue. No other mitigations are specified in the provided data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:37:41.038Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9adf7a7c5410652fd5f
Added to database: 09/26/2026, 13:33:33 UTC
Last enriched: 09/26/2026, 13:48:17 UTC
Last updated: 09/27/2026, 04:31:25 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.