PatchSiren

vrana CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vrana CVE published 2026-08-25

CVE-2026-34959

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER[REQUEST_URI] with no trusted-proxy check and no validation of the prefix value. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links. The vulnerability has a CVSS score of 5.3 and a severity of [truncated]