CVE-2026-15686CWE-253

CVE-2026-15686

High · published August 20, 2026

CVSS v3.0
7.2
EPSS
1%
Percentile
51.7
In the wild
Unconfirmed
What it is

Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability.

The specific flaw exists within the multi_query method. The issue results from an incorrect check of a function return value. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-28201.

The record
Technical detail
CVSS v3.0
7.2 · HIGH
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00724 · 51.7th percentile
Weakness
CWE-253 · Incorrect Check of Function Return Value
Published
2026-08-20T21:17Z
References (2)
EPSS history
Timeline
  • 20 AUG 16:25Z
    Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
    cvelistv5