PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-34959 vrana CVE debrief

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER[REQUEST_URI] with no trusted-proxy check and no validation of the prefix value. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected deployments should be reviewed and updated to version 5.5.0 or later. The X-Forwarded-Prefix header can be used to supply an absolute URL, leading to security risks. Security teams should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified.

Vendor
vrana
Product
adminer
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-08-26
Advisory published
2026-08-25
Advisory updated
2026-08-26

Who should care

Administrators and users of Adminer 4.6.0 before 5.5.0 should be aware of this vulnerability and take necessary actions to mitigate the risks. This includes reviewing and updating Adminer to version 5.5.0 or later, implementing trusted-proxy checks for the X-Forwarded-Prefix header, and validating the prefix value of the X-Forwarded-Prefix header. Additionally, monitoring for and restricting absolute URL values in the X-Forwarded-Prefix header can help prevent exploitation of this vulnerability. Security teams and operators should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Platform and asset owners should review relevant monitoring, detection, and logs for exposed assets that need extra review. This vulnerability may impact operators who use Adminer for database management and may require additional security measures to protect against potential attacks. Security teams should consider compensating controls for unauthenticated users and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Asset inventory and security teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. This vulnerability may require additional security measures to protect against potential attacks, including monitoring and detection, and may impact security teams who need to review and update their security controls. Security teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Security teams should also consider rollback/change windows and source tracking to address this vulnerability. Security teams should review compensating controls for exposed systems while remediation is scheduled and verified. Security teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams should track exceptions, retest remediated assets, and close the item,

Technical summary

The vulnerability in Adminer 4.6.0 before 5.5.0 is caused by the improper handling of the X-Forwarded-Prefix header. An attacker can supply an absolute URL in this header, which can lead to open redirects after state-changing POSTs, control of the session cookie path attribute, and poisoning of self-referential links. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability allows for open redirects, session cookie path attribute control, and link poisoning due to improper handling of the X-Forwarded-Prefix header. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.

Defensive priority

Medium-priority defensive actions are required to address this vulnerability.

Recommended defensive actions

  • Review and update Adminer to version 5.5.0 or later
  • Implement trusted-proxy checks for the X-Forwarded-Prefix header
  • Validate the prefix value of the X-Forwarded-Prefix header
  • Monitor for and restrict absolute URL values in the X-Forwarded-Prefix header
  • Consider compensating controls for unauthenticated users

Evidence notes

The CVE record and NVD entry provide details about the vulnerability in Adminer 4.6.0 before 5.5.0. The vulnerability allows for open redirects, session cookie path attribute control, and link poisoning due to improper handling of the X-Forwarded-Prefix header. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-34959 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-34959

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-34959 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34959

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.