PatchSiren cyber security CVE debrief
CVE-2026-34959 vrana CVE debrief
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER[REQUEST_URI] with no trusted-proxy check and no validation of the prefix value. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Affected deployments should be reviewed and updated to version 5.5.0 or later. The X-Forwarded-Prefix header can be used to supply an absolute URL, leading to security risks. Security teams should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified.
- Vendor
- vrana
- Product
- adminer
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of Adminer 4.6.0 before 5.5.0 should be aware of this vulnerability and take necessary actions to mitigate the risks. This includes reviewing and updating Adminer to version 5.5.0 or later, implementing trusted-proxy checks for the X-Forwarded-Prefix header, and validating the prefix value of the X-Forwarded-Prefix header. Additionally, monitoring for and restricting absolute URL values in the X-Forwarded-Prefix header can help prevent exploitation of this vulnerability. Security teams and operators should prioritize patching and compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management and security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Platform and asset owners should review relevant monitoring, detection, and logs for exposed assets that need extra review. This vulnerability may impact operators who use Adminer for database management and may require additional security measures to protect against potential attacks. Security teams should consider compensating controls for unauthenticated users and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Asset inventory and security teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. This vulnerability may require additional security measures to protect against potential attacks, including monitoring and detection, and may impact security teams who need to review and update their security controls. Security teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Security teams should also consider rollback/change windows and source tracking to address this vulnerability. Security teams should review compensating controls for exposed systems while remediation is scheduled and verified. Security teams should check relevant monitoring, detection, and logs for exposed assets that need extra review. Security teams should track exceptions, retest remediated assets, and close the item,
Technical summary
The vulnerability in Adminer 4.6.0 before 5.5.0 is caused by the improper handling of the X-Forwarded-Prefix header. An attacker can supply an absolute URL in this header, which can lead to open redirects after state-changing POSTs, control of the session cookie path attribute, and poisoning of self-referential links. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability allows for open redirects, session cookie path attribute control, and link poisoning due to improper handling of the X-Forwarded-Prefix header. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.
Defensive priority
Medium-priority defensive actions are required to address this vulnerability.
Recommended defensive actions
- Review and update Adminer to version 5.5.0 or later
- Implement trusted-proxy checks for the X-Forwarded-Prefix header
- Validate the prefix value of the X-Forwarded-Prefix header
- Monitor for and restrict absolute URL values in the X-Forwarded-Prefix header
- Consider compensating controls for unauthenticated users
Evidence notes
The CVE record and NVD entry provide details about the vulnerability in Adminer 4.6.0 before 5.5.0. The vulnerability allows for open redirects, session cookie path attribute control, and link poisoning due to improper handling of the X-Forwarded-Prefix header. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34959 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34959
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34959 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34959
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/vrana/adminer/security/advisories/GHSA-8478-xrj3-h9c2
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/adminer-before-open-redirect-via-x-forwarded-prefix
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.