CVE-2026-16434: Improper Input Validation in vrana adminer
Description
Adminer versions 4.6.0 through 5.5.0 contain an incomplete fix for a prior X-Forwarded-Prefix header validation issue. The vulnerability allows certain malformed prefixes with backslashes to bypass validation, leading to anomalous cookie-path scoping. Exploitation requires the ability to set the X-Forwarded-Prefix header, typically due to a misconfigured or absent reverse proxy. The issue was fixed in version 5.5.1. The impact is limited and considered low severity.
CVSS v4.0
Score 2.3low
Affected software
vrana
adminer
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16434 affects Adminer versions 4.6.0 through 5.5.0 and involves improper input validation of the X-Forwarded-Prefix header. The validation logic in bootstrap.inc.php rejects prefixes matching ^/[^/], blocking double forward slashes but allowing prefixes where the second character is a backslash (e.g., /\evil.com). Since browsers normalize backslashes to forward slashes, this malformed prefix survives into REQUEST_URI and influences the Set-Cookie Path attribute via cookie_path(). Successful exploitation requires that an attacker can set the X-Forwarded-Prefix header, which is possible if the reverse proxy is misconfigured or absent. The vulnerability leads to anomalous cookie-path scoping but does not escalate privileges or expose sensitive data. The issue was fixed in Adminer 5.5.1.
Potential Impact
The vulnerability allows attackers who can set the X-Forwarded-Prefix header to influence cookie path scoping by bypassing input validation with backslash characters. This can cause anomalous cookie-path behavior, potentially affecting cookie security boundaries. However, the impact is limited to cookie-path scoping anomalies and does not directly lead to privilege escalation or data disclosure. The CVSS score is low (2.3), reflecting the limited impact and the requirement for a specific misconfiguration to exploit.
Mitigation Recommendations
Upgrade Adminer to version 5.5.1 or later, where this issue is fixed. Ensure reverse proxies are correctly configured to prevent clients from setting the X-Forwarded-Prefix header. No other mitigations are necessary as the vulnerability requires this specific header manipulation and is fixed in the official patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-21T01:28:32.813Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8cf578acd9273b49842844
Added to database: 08/25/2026, 01:52:56 UTC
Last enriched: 09/10/2026, 20:48:03 UTC
Last updated: 10/08/2026, 18:48:43 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.