
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25892 is an unauthenticated persistent Denial-of-Service (DoS) vulnerability in Adminer, an open-source database management web application. The flaw exists in the ?script=version endpoint, which lacks origin validation and accepts POST data from any source, allowing an attacker to inject a PHP array type that causes a fatal TypeError in openssl_verify(), rendering the application unavailable to all users. Affected versions span from 4.6.2 through 5.4.1 (inclusive); version 5.4.2 contains the fix. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory). The vulnerability was published by the maintainer on February 8, 2026, and added to the NVD on February 9, 2026 (GitHub Advisory).
The root cause is improper input validation (CWE-20) in bootstrap.inc.php, where the ?script=version endpoint serializes and stores raw POST data — including $_POST["version"] — into /tmp/adminer.version without validating the parameter type or the request's origin. When an attacker submits version[] instead of version, PHP automatically coerces the value into an array. On the next page load, design.inc.php deserializes the file and passes the array to openssl_verify(), which in PHP 8.x throws a fatal TypeError: openssl_verify(): Argument #1 ($data) must be of type string, array given, causing an HTTP 500 response for all subsequent users. The poisoned state persists until the /tmp/adminer.version file is deleted, making this a persistent DoS rather than a transient one (GitHub Advisory, Patch Commit).
Successful exploitation results in complete unavailability of the Adminer database management interface for all users, as every subsequent page load returns HTTP 500 until the poisoned temp file is manually removed. There is no confidentiality or integrity impact — the attack is purely an availability disruption. Because Adminer is commonly used by developers and administrators to manage databases, an outage can indirectly block access to critical database operations and administrative workflows (GitHub Advisory).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any remote attacker with network access to the Adminer instance. A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, consisting of a single curl command (GitHub Advisory). The EPSS score is approximately 1.14% (per Feedly data), though the GitHub Advisory Database reports it at the 89th percentile (~4.46%). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. A Nuclei detection template has been added to the ProjectDiscovery nuclei-templates repository, facilitating automated scanning (Feedly).
curl -s -o /dev/null -w "%{http_code}\n" http://<target>/adminer.php?script=version endpoint with version[] (array syntax) instead of version (string). No authentication or CSRF token is required for this endpoint.curl -X POST "http://<target>/adminer.php?script=version" \
-d "signature=x&version[]=INJECTED"This writes a poisoned serialized PHP array to /tmp/adminer.version.openssl_verify() to receive an array instead of a string, throwing a fatal TypeError and returning HTTP 500 to all users.curl -s -o /dev/null -w "%{http_code}\n" http://<target>/adminer.php
# Returns: 500/tmp/adminer.version or upgrades to version 5.4.2. The attacker can re-poison the file after recovery to maintain the outage (GitHub Advisory).?script=version originating from non-browser clients or unknown IP addresses (legitimate requests originate from the browser of a logged-in user visiting adminer.org).POST /adminer.php?script=version with a 200 response followed immediately by GET /adminer.php returning 500; PHP error logs containing PHP Fatal error: Uncaught TypeError: openssl_verify(): Argument #1 ($data) must be of type string, array given./tmp/adminer.version (or the path defined by upload_tmp_dir) with serialized content containing an array for the version key, e.g., a:2:{s:9:"signature";s:1:"x";s:7:"version";a:1:{i:0;s:8:"INJECTED";}} instead of a plain string value (GitHub Advisory).The primary remediation is to upgrade Adminer to version 5.4.2 or later, which removes the vulnerable ?script=version server-side endpoint entirely and replaces the version-check mechanism with a direct client-side fetch to adminer.org (Adminer v5.4.2 Release, Patch Commit). If an immediate upgrade is not possible, the official advisory recommends making the /tmp/adminer.version file (or the equivalent upload_tmp_dir path) unwritable by the web server process, which prevents the poisoned file from being created. Additionally, deploying WAF rules to block POST requests to the ?script=version endpoint from untrusted sources, and restricting network access to the Adminer instance to trusted IP ranges, will reduce exposure (GitHub Advisory).
The vulnerability was reported by security researcher JoyGhoshs and promptly addressed by maintainer vrana with the release of Adminer 5.4.2 on February 8, 2026 (GitHub Advisory). The issue received community attention on Bluesky, with posts from security-focused accounts highlighting the unauthenticated nature of the attack. ProjectDiscovery added a Nuclei detection template for the vulnerability, reflecting community interest in automated detection. The vulnerability was also covered in a weekly threat landscape summary by Loginsoft on Medium.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."