CVE-2026-25892: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25892 is an unauthenticated persistent Denial-of-Service (DoS) vulnerability in Adminer, an open-source database management web application. The flaw exists in the ?script=version endpoint, which lacks origin validation and accepts POST data from any source, allowing an attacker to inject a PHP array type that causes a fatal TypeError in openssl_verify(), rendering the application unavailable to all users. Affected versions span from 4.6.2 through 5.4.1 (inclusive); version 5.4.2 contains the fix. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory). The vulnerability was published by the maintainer on February 8, 2026, and added to the NVD on February 9, 2026 (GitHub Advisory).

Technical details

The root cause is improper input validation (CWE-20) in bootstrap.inc.php, where the ?script=version endpoint serializes and stores raw POST data — including $_POST["version"] — into /tmp/adminer.version without validating the parameter type or the request's origin. When an attacker submits version[] instead of version, PHP automatically coerces the value into an array. On the next page load, design.inc.php deserializes the file and passes the array to openssl_verify(), which in PHP 8.x throws a fatal TypeError: openssl_verify(): Argument #1 ($data) must be of type string, array given, causing an HTTP 500 response for all subsequent users. The poisoned state persists until the /tmp/adminer.version file is deleted, making this a persistent DoS rather than a transient one (GitHub Advisory, Patch Commit).

Impact

Successful exploitation results in complete unavailability of the Adminer database management interface for all users, as every subsequent page load returns HTTP 500 until the poisoned temp file is manually removed. There is no confidentiality or integrity impact — the attack is purely an availability disruption. Because Adminer is commonly used by developers and administrators to manage databases, an outage can indirectly block access to critical database operations and administrative workflows (GitHub Advisory).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker with network access to the Adminer instance. A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, consisting of a single curl command (GitHub Advisory). The EPSS score is approximately 1.14% (per Feedly data), though the GitHub Advisory Database reports it at the 89th percentile (~4.46%). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. A Nuclei detection template has been added to the ProjectDiscovery nuclei-templates repository, facilitating automated scanning (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Adminer instances (versions 4.6.2–5.4.1) using tools like Shodan, Censys, or web crawlers searching for the Adminer login page.
  2. Verify target is accessible: Confirm the instance returns HTTP 200.
    curl -s -o /dev/null -w "%{http_code}\n" http://<target>/adminer.php
  3. Send the malicious POST request: Submit a POST to the ?script=version endpoint with version[] (array syntax) instead of version (string). No authentication or CSRF token is required for this endpoint.
    curl -X POST "http://<target>/adminer.php?script=version" \
      -d "signature=x&version[]=INJECTED"
    This writes a poisoned serialized PHP array to /tmp/adminer.version.
  4. Trigger the crash: Any subsequent request to the Adminer instance will cause openssl_verify() to receive an array instead of a string, throwing a fatal TypeError and returning HTTP 500 to all users.
    curl -s -o /dev/null -w "%{http_code}\n" http://<target>/adminer.php
    # Returns: 500
  5. Persistence: The DoS condition persists until an administrator manually deletes /tmp/adminer.version or upgrades to version 5.4.2. The attacker can re-poison the file after recovery to maintain the outage (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to ?script=version originating from non-browser clients or unknown IP addresses (legitimate requests originate from the browser of a logged-in user visiting adminer.org).
  • Logs: Web server access logs showing POST /adminer.php?script=version with a 200 response followed immediately by GET /adminer.php returning 500; PHP error logs containing PHP Fatal error: Uncaught TypeError: openssl_verify(): Argument #1 ($data) must be of type string, array given.
  • File System: Presence of /tmp/adminer.version (or the path defined by upload_tmp_dir) with serialized content containing an array for the version key, e.g., a:2:{s:9:"signature";s:1:"x";s:7:"version";a:1:{i:0;s:8:"INJECTED";}} instead of a plain string value (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Adminer to version 5.4.2 or later, which removes the vulnerable ?script=version server-side endpoint entirely and replaces the version-check mechanism with a direct client-side fetch to adminer.org (Adminer v5.4.2 Release, Patch Commit). If an immediate upgrade is not possible, the official advisory recommends making the /tmp/adminer.version file (or the equivalent upload_tmp_dir path) unwritable by the web server process, which prevents the poisoned file from being created. Additionally, deploying WAF rules to block POST requests to the ?script=version endpoint from untrusted sources, and restricting network access to the Adminer instance to trusted IP ranges, will reduce exposure (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher JoyGhoshs and promptly addressed by maintainer vrana with the release of Adminer 5.4.2 on February 8, 2026 (GitHub Advisory). The issue received community attention on Bluesky, with posts from security-focused accounts highlighting the unauthenticated nature of the attack. ProjectDiscovery added a Nuclei detection template for the vulnerability, reflecting community interest in automated detection. The vulnerability was also covered in a weekly threat landscape summary by Loginsoft on Medium.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

adminer

Fixed

sid

adminer

Fixed

trixie

adminer

Fixed

Ubuntu

Unknown

bionic (esm-apps)

adminer

Unknown

devel

adminer

Unknown

focal (esm-apps)

adminer

Unknown

jammy

adminer

Unknown

jammy (esm-apps)

adminer

Unknown

noble

adminer

Unknown

noble (esm-apps)

adminer

Unknown

resolute

adminer

Unknown

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management