CVE-2026-34959: Improper Input Validation in vrana adminer
Adminer versions 4.6.0 before 5.5.0 improperly validate the client-supplied X-Forwarded-Prefix header, allowing it to be prepended to the REQUEST_URI without trusted-proxy checks or validation. This flaw enables an authenticated attacker to cause open redirects after POST requests, control the session cookie path attribute without authentication, and poison self-referential links. However, injection of CR/LF characters is not possible, preventing header splitting or XSS attacks.
AI Analysis
Technical Summary
CVE-2026-34959 describes an improper input validation vulnerability in Adminer versions 4.6.0 up to but not including 5.5.0. The application prepends the X-Forwarded-Prefix header value directly to $_SERVER["REQUEST_URI"] without verifying if the header originates from a trusted proxy or validating the prefix content. An attacker can supply an absolute URL in this header, which is then used in Location redirect headers, Set-Cookie path attributes, and self-referential links. This leads to an authenticated open redirect after state-changing POST requests, unauthenticated control over the session cookie path attribute, and link poisoning. The vulnerability does not allow CR/LF injection, so header splitting and cross-site scripting are not feasible.
Potential Impact
The vulnerability allows an attacker with authentication to perform open redirects after POST requests, potentially redirecting users to malicious sites. Additionally, unauthenticated attackers can manipulate the session cookie path attribute, which may affect session handling and security. Poisoning of self-referential links could mislead users or affect application navigation. The inability to inject CR/LF characters limits the attacker's ability to perform header splitting or XSS attacks.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider restricting or validating the X-Forwarded-Prefix header at the proxy or application level to ensure it originates from trusted sources and contains only safe values.
CVE-2026-34959: Improper Input Validation in vrana adminer
Description
Adminer versions 4.6.0 before 5.5.0 improperly validate the client-supplied X-Forwarded-Prefix header, allowing it to be prepended to the REQUEST_URI without trusted-proxy checks or validation. This flaw enables an authenticated attacker to cause open redirects after POST requests, control the session cookie path attribute without authentication, and poison self-referential links. However, injection of CR/LF characters is not possible, preventing header splitting or XSS attacks.
CVSS v4.0
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-34959 describes an improper input validation vulnerability in Adminer versions 4.6.0 up to but not including 5.5.0. The application prepends the X-Forwarded-Prefix header value directly to $_SERVER["REQUEST_URI"] without verifying if the header originates from a trusted proxy or validating the prefix content. An attacker can supply an absolute URL in this header, which is then used in Location redirect headers, Set-Cookie path attributes, and self-referential links. This leads to an authenticated open redirect after state-changing POST requests, unauthenticated control over the session cookie path attribute, and link poisoning. The vulnerability does not allow CR/LF injection, so header splitting and cross-site scripting are not feasible.
Potential Impact
The vulnerability allows an attacker with authentication to perform open redirects after POST requests, potentially redirecting users to malicious sites. Additionally, unauthenticated attackers can manipulate the session cookie path attribute, which may affect session handling and security. Poisoning of self-referential links could mislead users or affect application navigation. The inability to inject CR/LF characters limits the attacker's ability to perform header splitting or XSS attacks.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider restricting or validating the X-Forwarded-Prefix header at the proxy or application level to ensure it originates from trusted sources and contains only safe values.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-03-31T17:58:43.753Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8cf578acd9273b49842848
Added to database: 08/25/2026, 01:52:56 UTC
Last enriched: 08/25/2026, 02:22:31 UTC
Last updated: 08/25/2026, 02:57:09 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.